CVE-2025-23196

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
21/01/2025
Last modified:
09/06/2025

Description

A code injection vulnerability exists in the Ambari Alert Definition <br /> feature, allowing authenticated users to inject and execute arbitrary <br /> shell commands. The vulnerability arises when defining alert scripts, <br /> where the script filename field is executed using `sh -c`. An attacker <br /> with authenticated access can exploit this vulnerability to inject <br /> malicious commands, leading to remote code execution on the server. The <br /> issue has been fixed in the latest versions of Ambari.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:ambari:*:*:*:*:*:*:*:* 2.7.9 (excluding)