Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8
Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious payloads.
Users are recommended to upgrade to version 2.7.8 which fixes this issue.
Metrics
Affected Vendors & Products
References
History
Wed, 28 May 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache ambari |
|
CPEs | cpe:2.3:a:apache:ambari:*:*:*:*:*:*:*:* | |
Vendors & Products |
Apache
Apache ambari |
Fri, 22 Nov 2024 12:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Thu, 07 Nov 2024 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Thu, 03 Oct 2024 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-20 | |
References |
|
Thu, 03 Oct 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 03 Oct 2024 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8 Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious payloads. Users are recommended to upgrade to version 2.7.8 which fixes this issue. | Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8 Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious payloads. Users are recommended to upgrade to version 2.7.8 which fixes this issue. |
Weaknesses | CWE-79 |

Status: PUBLISHED
Assigner: apache
Published: 2024-03-01T14:38:29.732Z
Updated: 2024-11-07T16:03:03.744Z
Reserved: 2023-12-07T14:02:23.087Z
Link: CVE-2023-50378

Updated: 2024-08-02T22:16:46.837Z

Status : Analyzed
Published: 2024-03-01T15:15:08.310
Modified: 2025-05-28T19:55:25.280
Link: CVE-2023-50378

No data.