CVE-2023-50378

CVE-2023-50378: Apache Ambari: Various XSS problems

Vendor Apache Software Foundation
Product Apache Ambari
Weakness CWE-79 · XSS
Published March 1, 2024
Last update November 7, 2024

CVSS base score

What the vulnerability does

Description

Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8    Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious payloads. Users are recommended to upgrade to version 2.7.8 which fixes this issue.

Key dates

Disclosure timeline

March 1, 2024 CVE published
November 7, 2024 Record updated