High severity8.0NVD Advisory· Published Jul 12, 2023· Updated Jun 17, 2026
CVE-2022-42009
CVE-2022-42009
Description
SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.ambari:ambariMaven | >= 2.7.0, < 2.7.7 | 2.7.7 |
Affected products
3- Apache Software Foundation/Apache Ambariv5Range: 2.7.0
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-m384-pj54-5vr2ghsaADVISORY
- lists.apache.org/thread/6xf477ttz1oxmg0bx0tpdoz2mlqd7sbcnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-42009ghsaADVISORY
News mentions
0No linked articles in our index yet.