https://seclists.org/oss-sec/2024/q1/162: CVE-2023-50379: Apache Ambari: authenticated users could perform command injection to perform RCE
Published Feb 27, 2024
·Updated
Affected Software
1 affected component
Apache Ambari>=2.7.0<2.7.8
Frequently Asked Questions
1
What is the severity of CVE-2023-50379?
The severity of CVE-2023-50379 is classified as important.
2
What versions of Apache Ambari are affected by CVE-2023-50379?
Apache Ambari versions 2.7.0 through 2.7.7 are affected by CVE-2023-50379.
3
How do I fix CVE-2023-50379?
To fix CVE-2023-50379, upgrade Apache Ambari to version 2.7.8 or later.
4
What type of vulnerability is CVE-2023-50379?
CVE-2023-50379 is a command injection vulnerability that could lead to remote code execution.
5
Who is impacted by CVE-2023-50379?
Cluster Operators using affected versions of Apache Ambari are impacted by CVE-2023-50379.