Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue.
Impact: A Cluster Operator can manipulate the request by adding a malicious code injection and gain a root over the cluster main host.
{ "nvd_published_at": "2024-02-27T09:15:36Z", "cwe_ids": [ "CWE-94" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2024-03-01T20:49:42Z" }