CVE-2023-23408
published 2023-03-14CVE-2023-23408: Azure Apache Ambari Spoofing Vulnerability Azure Apache Ambari Spoofing Vulnerability
medium4.5CVSS 3.1
AVNACLPRHUIRSUCNIHAN
EXPLOIT
EPSS
4.05%
89.9th percentile
Azure Apache Ambari Spoofing Vulnerability
Azure Apache Ambari Spoofing Vulnerability
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_hdinsight | >= 1.0 < 2302250400 | 2302250400 |
| msrc | azure_hdinsight | — | — |
CVSS provenance
nvdv3.14.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:H/A:N
cvelistv54.5MEDIUM
vendor_msrc4.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CVEList
Azure Apache Ambari Spoofing Vulnerability
cvelistv5·2023-03-14·CVSS 4.5
CVE-2023-23408 [MEDIUM] CWE-79 Azure Apache Ambari Spoofing Vulnerability
Azure Apache Ambari Spoofing Vulnerability
Azure Apache Ambari Spoofing Vulnerability
Microsoft
Azure Apache Ambari Spoofing Vulnerability
vendor_msrc·2023-03-14·CVSS 4.5
CVE-2023-23408 [MEDIUM] CWE-79 Azure Apache Ambari Spoofing Vulnerability
Azure Apache Ambari Spoofing Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker would have to send the victim a malicious URL that the victim would have to execute.
FAQ: According to the CVSS metric, privileges required is high (PR:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires the attacker or targeted user to have specific elevated privileges. Only users with roles “Cluster Admin” and “Cluster Operator” can access this.
Azure: Azure
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;DOS:N/A
Remediation: Release Notes
Ref
No detection rules found.
No writeups or analysis indexed.
2023-03-14
Published