CVE-2025-23196 - Ambari Shell Command Injection Vulnerability

CVE ID : CVE-2025-23196 Published : Jan. 21, 2025, 10:15 p.m. | 29 minutes ago Description : A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell commands. The vulnerability arises when defining alert scripts, where the script filename field is executed using `sh -c`. An attacker with authenticated access can exploit this vulnerability to inject malicious commands, leading to remote code execution on the server. The issue has been fixed in the latest versions of Ambari. Severity: 0.0 | NA Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Jan 21, 2025 - 23:45
 0  0
CVE-2025-23196 - Ambari Shell Command Injection Vulnerability
CVE ID : CVE-2025-23196
Published : Jan. 21, 2025, 10:15 p.m. | 29 minutes ago
Description : A code injection vulnerability exists in the Ambari Alert Definition feature, allowing authenticated users to inject and execute arbitrary shell commands. The vulnerability arises when defining alert scripts, where the script filename field is executed using `sh -c`. An attacker with authenticated access can exploit this vulnerability to inject malicious commands, leading to remote code execution on the server. The issue has been fixed in the latest versions of Ambari.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...