High severityNVD Advisory· Published Jul 12, 2023· Updated Oct 4, 2024
Apache Ambari: A malicious authenticated user can remotely execute arbitrary code in the context of the application.
CVE-2022-42009
Description
SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.ambari:ambariMaven | >= 2.7.0, < 2.7.7 | 2.7.7 |
Affected products
2- Apache Software Foundation/Apache Ambariv5Range: 2.7.0
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-m384-pj54-5vr2ghsaADVISORY
- lists.apache.org/thread/6xf477ttz1oxmg0bx0tpdoz2mlqd7sbcghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-42009ghsaADVISORY
News mentions
0No linked articles in our index yet.