CVE-2025-23195

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
21/01/2025
Last modified:
09/06/2025

Description

An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie <br /> project, allowing an attacker to inject malicious XML entities. This <br /> vulnerability occurs due to insecure parsing of XML input using the <br /> `DocumentBuilderFactory` class without disabling external entity <br /> resolution. An attacker can exploit this vulnerability to read arbitrary<br /> files on the server or perform server-side request forgery (SSRF) <br /> attacks. The issue has been fixed in both Ambari 2.7.9 and the trunk <br /> branch.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:ambari:*:*:*:*:*:*:*:* 2.7.9 (excluding)