Microsoft Azure Hdinsight vulnerabilities

10 known vulnerabilities affecting microsoft/azure_hdinsight.

Total CVEs
10
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH2MEDIUM7

Vulnerabilities

Page 1 of 1
CVE-2026-21529MEDIUMCVSS 5.4fixed in 5.1≥ 1.0, < 5.12026-02-10
CVE-2026-21529 [MEDIUM] CWE-79 CVE-2026-21529: Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsi Improper neutralization of input during web page generation ('cross-site scripting') in Azure HDInsights allows an authorized attacker to perform spoofing over a network.
cvelistv5nvd
CVE-2024-21330HIGHCVSS 7.8≥ 1.0, < omi-1.8.1-02024-03-12
CVE-2024-21330 [HIGH] CWE-122 CVE-2024-21330: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2023-36419CRITICALCVSS 9.8≥ 1.0, < 23082211282023-10-10
CVE-2023-36419 [HIGH] CWE-611 CVE-2023-36419: Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability Azure HDInsight Apache Oozie Workflow Scheduler XXE Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2023-38156HIGHCVSS 7.2≥ 1.0, < 23082211282023-09-12
CVE-2023-38156 [HIGH] CWE-20 CVE-2023-38156: Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability Azure HDInsight Apache Ambari JDBC Injection Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2023-36881MEDIUMCVSS 4.5≥ 1.0, < 23072012422023-08-08
CVE-2023-36881 [MEDIUM] CWE-79 Azure Apache Ambari Spoofing Vulnerability Azure Apache Ambari Spoofing Vulnerability Azure Apache Ambari Spoofing Vulnerability
cvelistv5
CVE-2023-35393MEDIUMCVSS 4.5≥ 1.0, < 23072012422023-08-08
CVE-2023-35393 [MEDIUM] CWE-79 Azure Apache Hive Spoofing Vulnerability Azure Apache Hive Spoofing Vulnerability Azure Apache Hive Spoofing Vulnerability
cvelistv5
CVE-2023-35394MEDIUMCVSS 4.6≥ 1.0, < 23072012422023-08-08
CVE-2023-35394 [MEDIUM] CWE-79 CVE-2023-35394: Azure HDInsight Jupyter Notebook Spoofing Vulnerability Azure HDInsight Jupyter Notebook Spoofing Vulnerability
cvelistv5nvd
CVE-2023-36877MEDIUMCVSS 4.5≥ 1.0, < 23072012422023-08-08
CVE-2023-36877 [MEDIUM] CWE-79 Azure Apache Oozie Spoofing Vulnerability Azure Apache Oozie Spoofing Vulnerability Azure Apache Oozie Spoofing Vulnerability
cvelistv5
CVE-2023-38188MEDIUMCVSS 4.5≥ 1.0, < 23072012422023-08-08
CVE-2023-38188 [MEDIUM] CWE-79 Azure Apache Hadoop Spoofing Vulnerability Azure Apache Hadoop Spoofing Vulnerability Azure Apache Hadoop Spoofing Vulnerability
cvelistv5
CVE-2023-23408MEDIUMCVSS 4.5PoC≥ 1.0, < 23022504002023-03-14
CVE-2023-23408 [MEDIUM] CWE-79 Azure Apache Ambari Spoofing Vulnerability Azure Apache Ambari Spoofing Vulnerability Azure Apache Ambari Spoofing Vulnerability
cvelistv5