{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2023-50378","assignerOrgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","state":"PUBLISHED","assignerShortName":"apache","dateReserved":"2023-12-07T14:02:23.087Z","datePublished":"2024-03-01T14:38:29.732Z","dateUpdated":"2024-11-07T16:03:03.744Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"Apache Ambari","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"2.7.7","status":"affected","version":"2.7.0","versionType":"semver"}]}],"descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"<span style=\"background-color: transparent;\">Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8&nbsp;&nbsp;<br><br>&nbsp;Impact : As it will be <span style=\"background-color: rgb(255, 255, 255);\">stored XSS,&nbsp;</span>Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious payloads. <br><br></span><span style=\"background-color: rgb(255, 255, 255);\">Users are recommended to upgrade to version  2.7.8 which fixes this issue.</span><br><br><br><br>"}],"value":"Lack of proper input validation and constraint enforcement in Apache Ambari prior to 2.7.8  \n\n Impact : As it will be stored XSS, Could be exploited to perform unauthorized actions, varying from data access to session hijacking and delivering malicious payloads. \n\nUsers are recommended to upgrade to version  2.7.8 which fixes this issue."}],"metrics":[{"other":{"content":{"text":"important"},"type":"Textual description of severity"}}],"problemTypes":[{"descriptions":[{"cweId":"CWE-79","description":"CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"f0158376-9dc2-43b6-827c-5f631a4d8d09","shortName":"apache","dateUpdated":"2024-10-03T12:23:16.421Z"},"references":[{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/6hn0thq743vz9gh283s2d87wz8tqh37c"}],"source":{"discovery":"UNKNOWN"},"title":"Apache Ambari: Various XSS problems","x_generator":{"engine":"Vulnogram 0.1.0-dev"}},"adp":[{"metrics":[{"cvssV3_1":{"scope":"CHANGED","version":"3.1","baseScore":6.1,"attackVector":"NETWORK","baseSeverity":"MEDIUM","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N","integrityImpact":"LOW","userInteraction":"REQUIRED","attackComplexity":"LOW","availabilityImpact":"NONE","privilegesRequired":"NONE","confidentialityImpact":"LOW"}},{"other":{"type":"ssvc","content":{"timestamp":"2024-03-05T19:28:57.526763Z","id":"CVE-2023-50378","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2024-11-07T16:03:03.744Z"}},{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-02T22:16:46.837Z"},"title":"CVE Program Container","references":[{"tags":["vendor-advisory","x_transferred"],"url":"https://lists.apache.org/thread/6hn0thq743vz9gh283s2d87wz8tqh37c"},{"url":"http://www.openwall.com/lists/oss-security/2024/03/01/5","tags":["x_transferred"]}]}]}}