CVE-2023-38156 is an Elevation of Privilege vulnerability affecting Microsoft Azure HDInsight Apache Ambari, stemming from a JDBC injection flaw. With a CVSS score of 7.2 (HIGH), this vulnerability allows a highly privileged attacker to achieve full compromise (confidentiality, integrity, availability) over the affected system with low attack complexity and no user interaction required. While there is no evidence of active exploitation (not in KEV) and no public exploit code available (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_hdinsight:-:*:*:*:*:*:*:* | ||
>= 1.0, < 2308221128CPE match | cpe:2.3:a:microsoft:azure_hdinsight:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.