Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue.
Impact: A Cluster Operator can manipulate the request by adding a malicious code injection and gain a root over the cluster main host.
{
"severity": "HIGH",
"github_reviewed": true,
"cwe_ids": [
"CWE-94"
],
"nvd_published_at": "2024-02-27T09:15:36Z",
"github_reviewed_at": "2024-03-01T20:49:42Z"
}