CVE-2023-23408HighCVSS 4.5
Azure Apache Ambari Spoofing Vulnerability
🔗 CVE IDs covered (1)
📋 Description
According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? An attacker would have to send the victim a malicious URL that the victim would have to execute.
According to the CVSS metric, privileges required is high (PR:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires the attacker or targeted user to have specific elevated privileges. Only users with roles “Cluster Admin” and “Cluster Operator” can access this.
🎯 Affected products1
- Azure HDInsight
✅ Remediation
KBRelease Notes (Security Update) — fixed build 2302250400