CVE-2025-23196 – Ambari Shell Command Injection Vulnerability

The following table lists the changes that have been made to the
CVE-2025-23196 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.

  • New CVE Received
    by [email protected]

    Jan. 21, 2025

    Action Type Old Value New Value
    Added Description A code injection vulnerability exists in the Ambari Alert Definition
    feature, allowing authenticated users to inject and execute arbitrary
    shell commands. The vulnerability arises when defining alert scripts,
    where the script filename field is executed using `sh -c`. An attacker
    with authenticated access can exploit this vulnerability to inject
    malicious commands, leading to remote code execution on the server. The
    issue has been fixed in the latest versions of Ambari.
    Added CWE CWE-77
    Added Reference https://lists.apache.org/thread/70g1l5lxvko7kvhyxmtmklhhfrlon837
Share the Post:

Related Posts