From 1254bc10549ad9c816a1d95b692c08d3a89d8eb0 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Tue, 28 Jan 2025 19:47:33 +0000 Subject: [PATCH] Publish GHSA-qrp9-23p7-g5mf --- .../2024/02/GHSA-qrp9-23p7-g5mf/GHSA-qrp9-23p7-g5mf.json | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/advisories/github-reviewed/2024/02/GHSA-qrp9-23p7-g5mf/GHSA-qrp9-23p7-g5mf.json b/advisories/github-reviewed/2024/02/GHSA-qrp9-23p7-g5mf/GHSA-qrp9-23p7-g5mf.json index aac023c717f..0dd0ac8a93e 100644 --- a/advisories/github-reviewed/2024/02/GHSA-qrp9-23p7-g5mf/GHSA-qrp9-23p7-g5mf.json +++ b/advisories/github-reviewed/2024/02/GHSA-qrp9-23p7-g5mf/GHSA-qrp9-23p7-g5mf.json @@ -1,14 +1,19 @@ { "schema_version": "1.4.0", "id": "GHSA-qrp9-23p7-g5mf", - "modified": "2024-02-27T21:53:34Z", + "modified": "2025-01-28T19:46:05Z", "published": "2024-02-27T18:31:02Z", "aliases": [ "CVE-2023-50380" ], "summary": "Apache Ambari XML External Entity injection", "details": "XML External Entity injection in Apache Ambari versions <= 2.7.7, Users are recommended to upgrade to version 2.7.8, which fixes this issue.\n\nMore Details:\n\nOozie Workflow Scheduler had a vulnerability that allowed for root-level file reading and privilege escalation from low-privilege users. The vulnerability was caused through lack of proper user input validation.\n\nThis vulnerability is known as an XML External Entity (XXE) injection attack. Attackers can exploit XXE vulnerabilities to read arbitrary files on the server, including sensitive system files. In theory, it might be possible to use this to escalate privileges.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [ { "package": {