GHSA-9q6v-rxmw-g3gh

Suggest an improvement
Source
https://github.com/advisories/GHSA-9q6v-rxmw-g3gh
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/03/GHSA-9q6v-rxmw-g3gh/GHSA-9q6v-rxmw-g3gh.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-9q6v-rxmw-g3gh
Aliases
  • CVE-2023-50378
Published
2024-03-01T15:31:38Z
Modified
2024-10-03T18:26:54.622394Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N CVSS Calculator
Summary
Apache Ambari: Various Cross site scripting problems
Details

Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8  

 Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious payloads.

Users are recommended to upgrade to version 2.7.8 which fixes this issue.

Database specific
{
    "nvd_published_at": "2024-03-01T15:15:08Z",
    "cwe_ids": [
        "CWE-20",
        "CWE-79"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-03-01T21:44:45Z"
}
References

Affected packages

Maven / org.apache.ambari:ambari

Package

Name
org.apache.ambari:ambari
View open source insights on deps.dev
Purl
pkg:maven/org.apache.ambari/ambari

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.7.8

Affected versions

1.*

1.7.0.0

2.*

2.0.0.0