Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability
CVE-2023-38156

7.2HIGH

Key Information:

Vendor
Microsoft
Vendor
CVE Published:
12 September 2023

Badges

📰 News Worthy

Summary

A vulnerability has been identified in Azure HDInsight that allows attackers to exploit a JDBC injection flaw within the Apache Ambari interface. This weakness can lead to unauthorized elevation of privileges, potentially enabling an attacker to gain inappropriate access to system resources. Organizations using Azure HDInsight should promptly apply recommended mitigations and updates to safeguard their systems against potential exploitation of this vulnerability.

Affected Version(s)

Azure HDInsight Unknown 1.0 < 2308221128

News Articles

Microsoft Azure HDInsight Bugs Expose Big Data to Breaches

Security holes in a big data tool can open the door to big data compromises.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • 📰

    First article discovered by Dark Reading

  • Vulnerability published

  • Vulnerability Reserved

.