https://seclists.org/oss-sec/2024/q1/167: CVE-2023-50380: Apache Ambari: authenticated users could perform XXE to read arbitrary files on the server
Published Feb 27, 2024
·Updated
Affected Software
1 affected component
Apache Ambari>=2.7.0<=2.7.7
Frequently Asked Questions
1
What is the severity of CVE-2023-50380?
The severity of CVE-2023-50380 is classified as important.
2
What versions of Apache Ambari are affected by CVE-2023-50380?
CVE-2023-50380 affects Apache Ambari versions 2.7.0 through 2.7.7.
3
How can I fix CVE-2023-50380?
To fix CVE-2023-50380, users are recommended to upgrade to Apache Ambari version 2.7.8 or later.
4
What type of vulnerability is CVE-2023-50380?
CVE-2023-50380 is an XML External Entity (XXE) injection vulnerability.
5
What can users do to protect against CVE-2023-50380?
Users can protect against CVE-2023-50380 by ensuring they are using an updated version of Apache Ambari, specifically version 2.7.8 or higher.