Threat Advisory

Experts Detail New Flaws in Azure HDInsight Spark, Kafka, and Hadoop Services

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

The three newly discovered security vulnerabilities in Azure HDInsight's Apache Hadoop, Kafka, and Spark services. These vulnerabilities could lead to privilege escalation and a denial-of-service condition. Orca security researcher Lidor Ben Shitrit identified these vulnerabilities, affecting authenticated users of Azure HDInsight services such as Apache Ambari and Apache Oozie.[/subscribe_to_unlock_form]

Summary:

The three newly discovered security vulnerabilities in Azure HDInsight's Apache Hadoop, Kafka, and Spark services. These vulnerabilities could lead to privilege escalation and a denial-of-service condition. Orca security researcher Lidor Ben Shitrit identified these vulnerabilities, affecting authenticated users of Azure HDInsight services such as Apache Ambari and Apache Oozie.[emaillocker id="1283"]

  • CVE-2023-36419 - Azure HDInsight Apache Oozie Workflow Scheduler XML External Entity (XXE) Injection Elevation of Privilege Vulnerability.
  • CVE-2023-38156 - Azure HDInsight Apache Ambari Java Database Connectivity (JDBC) Injection Elevation of Privilege Vulnerability
  • Azure HDInsight Apache Oozie Regular Expression Denial-of-Service (ReDoS) Vulnerability (no CVE)

These flaws could be exploited by authenticated attackers to gain cluster administrator privileges or disrupt system operations. The XXE flaw allows for root-level file reading and privilege escalation, while the JDBC injection flaw could lead to obtaining a reverse shell as root. The ReDoS vulnerability, caused by a lack of input validation, can result in a denial-of-service attack, impacting system availability and reliability.

Recommendations:

We strongly recommend you update the Azure HDInsight Apache JDBC Elevation in Ambari and the Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation. Please find the download link below.

References:

The following reports contain further technical details:

https://thehackernews.com/2024/02/high-severity-flaws-found-in-azure.html

[/emaillocker]
crossmenu