CVE-2023-36419 is a critical XML External Entity (XXE) Elevation of Privilege vulnerability affecting Azure HDInsight Apache Oozie Workflow Scheduler. With a CVSS score of 9.8, this network-exploitable flaw requires no user interaction and allows for complete compromise of confidentiality, integrity, and availability. While not currently listed on the KEV catalog or having public exploit code, its high FAUCET Risk Score and mention in patch Tuesday articles indicate significant potential for future exploitation and warrants immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_hdinsight:-:*:*:*:*:*:*:* | ||
>= 1.0, < 2308221128CPE match | cpe:2.3:a:microsoft:azure_hdinsight:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.