SpringEL injection in the metrics source in Apache Ambari version 2.7.0 to 2.7.6 allows a malicious authenticated user to execute arbitrary code remotely. Users are recommended to upgrade to 2.7.7.
2023-07-12T10:15:09.547
2024-11-21T07:29:50.737
Modified
CVSSv3.1: 8.0 (HIGH)