Open Nav
Sign Up

New Vulnerabilities in Azure HDInsight Services

Bar Refael

February 7, 2024

Recent discoveries have unveiled three significant security vulnerabilities within Azure HDInsight’s Apache Hadoop, Kafka, and Spark services. These vulnerabilities pose risks of privilege escalation and a regular expression denial-of-service (ReDoS) condition, affecting authenticated users across various Azure HDInsight services, including Apache Ambari and Apache Oozie.

Vulnerability Details

  • CVE-2023-36419 (CVSS score: 8.8): This vulnerability in Azure HDInsight Apache Oozie Workflow Scheduler involves XML External Entity (XXE) Injection, leading to elevation of privilege. It results from insufficient user input validation, enabling attackers to read root-level files and escalate privileges.
  • CVE-2023-38156 (CVSS score: 7.2): Found in Azure HDInsight Apache Ambari, this Java Database Connectivity (JDBC) Injection vulnerability also facilitates elevation of privilege. Attackers can exploit this flaw to execute a specially crafted network request, potentially obtaining a reverse shell as root.
  • Azure HDInsight Apache Oozie Regular Expression Denial-of-Service (ReDoS) Vulnerability: This flaw, while not assigned a CVE, stems from inadequate input validation, allowing attackers to initiate an intensive loop operation through a large range of action IDs, causing DoS.

Attack Scenario and Exploitation

These vulnerabilities enable an authenticated attacker with access to the target HDI cluster to gain cluster administrator privileges through specially crafted network requests. The XXE and JDBC injection flaws specifically allow for privilege escalation, while the ReDoS vulnerability can severely disrupt system operations, degrade performance, and impact service availability and reliability.

Response and Mitigation

Microsoft has addressed these vulnerabilities by releasing fixes on October 26, 2023, following responsible disclosure protocols. Organizations using Azure HDInsight services are strongly encouraged to apply these updates promptly to mitigate the risks associated with these vulnerabilities.

Threat Landscape and Impact

The discovery of these vulnerabilities highlights the ongoing security challenges within cloud services and the potential for exploitation that can lead to unauthorized data access, system disruption, and compromised system integrity. It follows previous disclosures by Orca Security, which detailed vulnerabilities in the same ecosystem capable of data access, session hijacking, and malicious payload delivery.

Additionally, Orca Security’s recent findings regarding Google Cloud Dataproc clusters underscore the broader issue of security risks in cloud environments, emphasizing the need for stringent security controls and vigilant management of cloud resources.

Conclusion

The identification of new vulnerabilities in Azure HDInsight’s services serves as a critical reminder of the importance of regular security assessments, prompt patch management, and the adoption of comprehensive security measures to protect cloud environments against emerging threats. Organizations must remain proactive in their security practices to safeguard their cloud infrastructure and sensitive data against potential exploitation.

Stay safe and informed,

OP Innovate.

Resources highlights

Critical Check Point VPN RCE Flaws CVE-2026-85102 and CVE-2026-85103 Face Imminent Exploitation Risk

Check Point has released security updates for two critical vulnerabilities affecting its VPN infrastructure that could allow unauthenticated remote attackers to execute arbitrary code on…

Read more >

check point_cve-2026-85102-cve-2026-85103

SonicWall SMA1000 Zero-Days CVE-2026-83548 and CVE-2026-83549 Exploited for Unauthenticated RCE

SonicWall has disclosed two actively exploited zero-day vulnerabilities affecting its SMA1000 secure remote access appliances. The vulnerabilities, tracked as CVE-2026-83548 and CVE-2026-83549, affect the SMA1000…

Read more >

sonicwall sma1000_cve-2026-83548-83549

PaperCut CVE-2026-81578 and CVE-2026-82078 Exploited for Pre-Auth RCE

Threat actors are actively exploiting two vulnerabilities in PaperCut NG and PaperCut MF that can be chained to bypass authentication and achieve remote code execution…

Read more >

papercut_cve-2026-81578-82078

Next.js Critical Vulnerabilities Enable Unauthenticated RCE

Vercel has released security updates for two critical vulnerabilities in Next.js that could allow unauthenticated attackers to achieve remote code execution on vulnerable applications. The…

Read more >

next.js

Keycloak CVE-2026-18963 Enables Unauthenticated Account Takeover

A critical vulnerability in Keycloak could allow an unauthenticated remote attacker to take control of arbitrary user accounts through the platform's password recovery functionality. Tracked…

Read more >

cve-2026-18963

Elementor Pro CVE-2026-32475 Enables Unauthenticated File Upload and RCE

A critical vulnerability in the widely deployed Elementor Pro plugin for WordPress can allow unauthenticated attackers to bypass file-type restrictions, upload executable PHP files to…

Read more >

CVE-2026-32475
Under Cyber Attack?

Fill out the form and we will contact you immediately.