CVE-2025-23196
Severity CVSS v4.0:
Pending analysis
Type:
CWE-77
Command Injection
Publication date:
21/01/2025
Last modified:
09/06/2025
Description
A code injection vulnerability exists in the Ambari Alert Definition <br />
feature, allowing authenticated users to inject and execute arbitrary <br />
shell commands. The vulnerability arises when defining alert scripts, <br />
where the script filename field is executed using `sh -c`. An attacker <br />
with authenticated access can exploit this vulnerability to inject <br />
malicious commands, leading to remote code execution on the server. The <br />
issue has been fixed in the latest versions of Ambari.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:apache:ambari:*:*:*:*:*:*:*:* | 2.7.9 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



