Description
SpringEL injection in the server agent in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7.
Remediation
References
https://lists.apache.org/thread/6xf477ttz1oxmg0bx0tpdoz2mlqd7sbc
Related Vulnerabilities
CVE-2020-13941 Vulnerability in maven package org.apache.solr:solr-core
CVE-2019-3795 Vulnerability in maven package org.springframework.security:spring-security-core
CVE-2020-26272 Vulnerability in maven package org.webjars.npm:electron
CVE-2023-26269 Vulnerability in maven package org.apache.james:james-server-cli
CVE-2023-31206 Vulnerability in maven package org.apache.inlong:manager-web