https://seclists.org/oss-sec/2025/q1/41: CVE-2025-23195: Apache Ambari: XML External Entity (XXE) Vulnerability in Ambari/Oozie
Published Jan 21, 2025
·Updated
Affected Software
1 affected component
Apache Ambari<2.7.9
Frequently Asked Questions
1
What is the severity of CVE-2025-23195?
The severity of CVE-2025-23195 is rated as moderate.
2
Which versions of Apache Ambari are affected by CVE-2025-23195?
CVE-2025-23195 affects versions of Apache Ambari before 2.7.9.
3
What type of vulnerability is CVE-2025-23195?
CVE-2025-23195 is an XML External Entity (XXE) vulnerability.
4
How can I fix CVE-2025-23195?
To fix CVE-2025-23195, upgrade to Apache Ambari version 2.7.9 or later.
5
What risks does CVE-2025-23195 pose to Apache Ambari users?
CVE-2025-23195 allows attackers to inject malicious XML entities, potentially leading to sensitive data exposure.