Trunin Mikhail created AMBARI-25369:
---------------------------------------
Summary: SSTI in Ambari config
Key: AMBARI-25369
URL: https://issues.apache.org/jira/browse/AMBARI-25369
Project: Ambari
Issue Type: Bug
Components: ambari-admin
Affects Versions: 1.7.0, 2.7.3
Environment: Tested in 2.7.3, 1.7.0
Reporter: Trunin Mikhail
Hello, i found SSTI to RCE vulnerability in Apache ambari, and i send three
mails with technical details to [[email protected],
|mailto:[email protected]] [[email protected] and
|mailto:[email protected]]
[[email protected]|mailto:[email protected]]
In dates: 4 jul 2019, 8 aug 2019, and 24 aug 2019, but you not responce, bug is
critical, and i want cve approve, help me?
best regards
--
This message was sent by Atlassian Jira
(v8.3.2#803003)