QID 378771

Date Published: 2023-08-17

QID 378771: Apache Ambari Arbitrary Code Execution Vulnerability

Apache Ambari is a software project of the Apache Software Foundation. Ambari enables system administrators to provision, manage and monitor a Hadoop cluster, and also to integrate Hadoop with the existing enterprise infrastructure.
CVE-2022-45855 and CVE-2022-42009 : SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7.

Affected Version:
Apache Ambari 2.7.0 to 2.7.6

QID Detection Logic:(Authenticated)
This QID checks if vulnerable version of Apache Ambari is running or not by checking "/var/lib/ambari-server/resources/version"

Successful exploitation could lead to Arbitrary Code Execution Vulnerability.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Customers are advised to update Apache Ambari to 2.7.7.

    CVEs related to QID 378771

    Software Advisories
    Advisory ID Software Component Link
    Apache Ambari URL Logo lists.apache.org/thread/6xf477ttz1oxmg0bx0tpdoz2mlqd7sbc
    Apache Ambari URL Logo lists.apache.org/thread/302c4hwfjy9lx63jrbhcdx948pxc54l1