Azure HDInsight has been identified with multiple Cross-Site Scripting – XSS vulnerabilities related to Stored XSS and Reflected XSS. The severity for these vulnerabilities ranges between 4.5 (Medium) and 4.6 (Medium).
These vulnerabilities have affected multiple products, including Azure Apache Oozie, Apache Ambari, Jupyter Notebooks, Apache Hadoop, and Apache Hive 2. However, Microsoft fixed these vulnerabilities on their 8th August Security update.
As per the reports shared with Cyber Security News, 6 Stored XSS vulnerabilities and 2 Reflected XSS vulnerabilities were discovered, of which 4 of the Stored XSS vulnerabilities existed on the Apache Ambari.
These vulnerabilities were related to YARN Configurations, YARN Queue Manager, Background Operations, and Managed Notifications. All of these vulnerabilities are categorized under CVE-2023-36881.
The other two Stored XSS existed on the Jupyter Notebooks and Apache Woozie, categorized under CVE-2023-35394 and CVE-2023-36877, respectively.
CVE-2023-35394 was related to a Code Execution in the Jupyter Notebooks and had a severity of 4.6 (Medium), whereas CVE-2023-36877 was related to a Web Console Stored XSS and had a severity of 4.5 (Medium).
With DoControl, you can keep your SaaS applications and data safe and secure by creating workflows tailored to your needs. It’s an easy and efficient way to identify and manage risks. You can mitigate the risk and exposure of your organization’s SaaS applications in just a few simple steps.
Furthermore, the two reflected XSS vulnerabilities on the Apache Hadoop and Apache Hive 2 and have been categorized under CVE-2023-38188 and CVE-2023-35393. Both vulnerabilities had a severity of 4.5 (Medium) and can be triggered via endpoint manipulation.
The list of the vulnerabilities mentioned, their severity, and CVE ID can be found in the following table.
S.No | Name | Severity | XSS Type | Impact | Severity | CVE |
1 | Azure HDInsight/Apache Ambari Stored XSS in Background Operations | Important | Stored XSS | Spoofing | 4.5 | CVE-2023-36881 |
2 | Azure HDInsight/Apache Ambari Stored XSS via Managed Notifications | Important | Stored XSS | Spoofing | 4.5 | CVE-2023-36881 |
3 | Azure HDInsight/Apache Ambari Stored XSS in YARN Queue Manager | Important | Stored XSS | Spoofing | 4.5 | CVE-2023-36881 |
4 | Azure HDInsight/Jupyter Notebooks Code Execution via Stored XSS | Important | Stored XSS | Spoofing | 4.6 | CVE-2023-35394 |
5 | Azure HDInsight/Apache Hadoop Reflected XSS via endpoint manipulation | Important | Reflected XSS | Spoofing | 4.5 | CVE-2023-38188 |
6 | Azure HDInsight/Apache Hive 2 Reflected XSS via endpoint manipulation | Important | Reflected XSS | Spoofing | 4.5 | CVE-2023-35393 |
7 | Azure HDInsight/Apache Ambari Stored XSS in YARN Configurations | Important | Stored XSS | Spoofing | 4.5 | CVE-2023-36881 |
8 | Azure HDInsight/Apache Oozie Web Console Stored XSS via Custom Filter | Important | Stored XSS | Spoofing | 4.5 | CVE-2023-36877 |
Orca Security has published a complete report, providing detailed information about the exploitation, proof-of-concept, and other information. Users of these products should upgrade to the latest version to prevent these vulnerabilities from getting exploited.
Keep informed about the latest Cyber Security News by following us on Google News, Linkedin, Twitter, and Facebook.
A sophisticated cyber campaign orchestrated by the Chinese Advanced Persistent Threat (APT) group, Silver Fox,…
A new wave of cyberattacks attributed to the Ghostwriter Advanced Persistent Threat (APT) group has…
The LCRYX ransomware, a malicious VBScript-based threat, has re-emerged in February 2025 after its initial…
Recent cybersecurity investigations have uncovered a sophisticated technique employed by threat actors to evade detection…
A financial management app named Finance Simplified has been revealed as a malicious tool for…
A recent discovery by cybersecurity researchers has revealed that the Poseidon malware, a macOS-targeting trojan,…