High severityNVD Advisory· Published Jul 12, 2023· Updated Oct 4, 2024
Apache Ambari: Allows authenticated metrics consumers to perform RCE
CVE-2022-45855
Description
SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.ambari:ambariMaven | >= 2.7.0, < 2.7.7 | 2.7.7 |
Affected products
2- Apache Software Foundation/Apache Ambariv5Range: 2.7.0
Patches
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-p7w2-784m-qpq9ghsaADVISORY
- lists.apache.org/thread/302c4hwfjy9lx63jrbhcdx948pxc54l1ghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-45855ghsaADVISORY
News mentions
0No linked articles in our index yet.