A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability occurs when processing alert definitions, where malicious input can be injected into the alert script execution path. An attacker with authenticated access can exploit this vulnerability to execute arbitrary commands on the server. The issue has been fixed in the latest versions of Ambari.
History

Wed, 22 Jan 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 21 Jan 2025 23:45:00 +0000

Type Values Removed Values Added
References

Tue, 21 Jan 2025 21:30:00 +0000

Type Values Removed Values Added
Description A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability occurs when processing alert definitions, where malicious input can be injected into the alert script execution path. An attacker with authenticated access can exploit this vulnerability to execute arbitrary commands on the server. The issue has been fixed in the latest versions of Ambari.
Title Apache Ambari: Remote Code Injection in Ambari Metrics and AMS Alerts
Weaknesses CWE-75
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2025-01-22T14:46:09.923Z

Reserved: 2024-11-04T11:47:16.721Z

Link: CVE-2024-51941

cve-icon Vulnrichment

Updated: 2025-01-21T23:02:41.810Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-01-21T22:15:12.447

Modified: 2025-01-22T15:15:14.247

Link: CVE-2024-51941

cve-icon Redhat

No data.