Affected versions:

- Apache Ambari 2.7.0 through 2.7.6

Description:

SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 
allows a malicious authenticated user to execute arbitrary code remotely. Users 
are recommended to upgrade to 2.7.7.

Credit:

Jecki Go ([email protected]) (finder)

References:

https://ambari.apache.org/
https://www.cve.org/CVERecord?id=CVE-2022-42009


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to