https://seclists.org/oss-sec/2025/q1/42: CVE-2025-23196: Apache Ambari: Code Injection Vulnerability in Ambari Alert Definition
Published Jan 21, 2025
·Updated
Affected Software
1 affected component
Apache Ambari<2.7.9
Frequently Asked Questions
1
What is the severity of CVE-2025-23196?
The severity of CVE-2025-23196 is classified as important.
2
What versions of Apache Ambari are affected by CVE-2025-23196?
Apache Ambari versions prior to 2.7.9 are affected by CVE-2025-23196.
3
How do I fix CVE-2025-23196?
To fix CVE-2025-23196, upgrade Apache Ambari to version 2.7.9 or later.
4
What type of vulnerability is CVE-2025-23196?
CVE-2025-23196 is a code injection vulnerability that allows authenticated users to execute arbitrary shell commands.
5
Who can be affected by CVE-2025-23196?
Authenticated users of Apache Ambari can be affected by CVE-2025-23196 due to the ability to inject code.