Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8  

 Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious payloads.

Users are recommended to upgrade to version 2.7.8 which fixes this issue.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9q6v-rxmw-g3gh Apache Ambari: Various Cross site scripting problems
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Thu, 29 May 2025 05:15:00 +0900

Type Values Removed Values Added
First Time appeared Apache
Apache ambari
CPEs cpe:2.3:a:apache:ambari:*:*:*:*:*:*:*:*
Vendors & Products Apache
Apache ambari

Fri, 22 Nov 2024 21:00:00 +0900

Type Values Removed Values Added
References

Fri, 08 Nov 2024 01:15:00 +0900

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Thu, 03 Oct 2024 22:45:00 +0900

Type Values Removed Values Added
Weaknesses CWE-20
References

Thu, 03 Oct 2024 22:30:00 +0900

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Oct 2024 21:30:00 +0900

Type Values Removed Values Added
Description Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8    Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious payloads. Users are recommended to upgrade to version 2.7.8 which fixes this issue. Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8    Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious payloads. Users are recommended to upgrade to version 2.7.8 which fixes this issue.
Weaknesses CWE-79

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-11-07T16:03:03.744Z

Reserved: 2023-12-07T14:02:23.087Z

Link: CVE-2023-50378

cve-icon Vulnrichment

Updated: 2024-08-02T22:16:46.837Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-01T15:15:08.310

Modified: 2025-05-28T19:55:25.280

Link: CVE-2023-50378

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses