CVE-2025-23195 – Ambari Oozie XXE Injection

The following table lists the changes that have been made to the
CVE-2025-23195 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jan. 21, 2025

    Action Type Old Value New Value
    Added Description An XML External Entity (XXE) vulnerability exists in the Ambari/Oozie
    project, allowing an attacker to inject malicious XML entities. This
    vulnerability occurs due to insecure parsing of XML input using the
    `DocumentBuilderFactory` class without disabling external entity
    resolution. An attacker can exploit this vulnerability to read arbitrary
    files on the server or perform server-side request forgery (SSRF)
    attacks. The issue has been fixed in both Ambari 2.7.9 and the trunk
    branch.
    Added CWE CWE-611
    Added Reference https://lists.apache.org/thread/hsb6mvxd7g37dq1ygtd0pd88gs9tfcwq
Share the Post:

Related Posts