[MAVEN:GHSA-J76Q-99X2-V7VQ] Apache Ambari Improper Access Control

Severity Critical
Affected Packages 1
Fixed Packages 1
CVEs 1

Custom commands may be executed on Ambari Agent (2.4.x, before 2.4.2) hosts without authorization, leading to unauthorized access to operations that may affect the underlying system. Such operations are invoked by the Ambari Agent process on Ambari Agent hosts, as the user executing the Ambari Agent process.

Package Affected Version
pkg:maven/org.apache.ambari/ambari >= 2.4.0, < 2.4.2
Package Fixed Version
pkg:maven/org.apache.ambari/ambari = 2.4.2
ID
MAVEN:GHSA-J76Q-99X2-V7VQ
Severity
critical
URL
https://github.com/advisories/GHSA-j76q-99x2-v7vq
Published
2022-05-17T02:51:56
(2 years ago)
Modified
2023-11-07T17:56:12
(10 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.apache.ambari/ambari org.apache.ambari ambari >= 2.4.0 < 2.4.2
Fixed pkg:maven/org.apache.ambari/ambari org.apache.ambari ambari = 2.4.2
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...