CVE Database
/

CVE-2024-51941

Back to search

CVE-2024-51941

Published: Jan 21, 2025

Modified: Sep 3, 2025

PUBLISHED

Description

A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability occurs when processing alert definitions, where malicious input can be injected into the alert script execution path. An attacker with authenticated access can exploit this vulnerability to execute arbitrary commands on the server. The issue has been fixed in the latest versions of Ambari.

VendorProductVersions

Apache Software Foundation

Apache Ambari

affected
0 - <= 2.7.8

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now