Vulnerabilities > Apache > Ambari > 2.7.7

DATE CVE VULNERABILITY TITLE RISK
2024-02-27 CVE-2023-50380 Unspecified vulnerability in Apache Ambari
XML External Entity injection in apache ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue. More Details: Oozie Workflow Scheduler had a vulnerability that allowed for root-level file reading and privilege escalation from low-privilege users.
network
low complexity
apache
6.5