CVE-2024-51941 – Apache Ambari Remote Code Injection Vulnerability

The following table lists the changes that have been made to the
CVE-2024-51941 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jan. 21, 2025

    Action Type Old Value New Value
    Added Description A remote code injection vulnerability exists in the Ambari Metrics and
    AMS Alerts feature, allowing authenticated users to inject and execute
    arbitrary code. The vulnerability occurs when processing alert
    definitions, where malicious input can be injected into the alert script
    execution path. An attacker with authenticated access can exploit this
    vulnerability to execute arbitrary commands on the server. The issue has
    been fixed in the latest versions of Ambari.
    Added CWE CWE-75
    Added Reference https://lists.apache.org/thread/xq50nlff7o7z1kq3y637clzzl6mjhl8j
Share the Post:

Related Posts