Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Contribution] Add Azure HDInsight DoS and privesc #258

Open
0xdabbad00 opened this issue Dec 7, 2023 · 0 comments
Open

[Contribution] Add Azure HDInsight DoS and privesc #258

0xdabbad00 opened this issue Dec 7, 2023 · 0 comments
Labels
addition New security issue or vulnerability azure Issue related to an Azure service

Comments

@0xdabbad00
Copy link
Contributor

Summary (give a brief description of the issue)

3 vulns were found by Orca in Azure HDInsight requiring authenticated access to the cluster, with two of them allowing privilege escalation and the 3rd just being DoS. This seems Low or Medium severity to me due to requiring authenticated access.

References (provide links to blogposts, etc.)

https://msrc.microsoft.com/blog/2023/12/microsoft-mitigates-three-vulnerabilities-in-azure-hdinsight/

@0xdabbad00 0xdabbad00 added the addition New security issue or vulnerability label Dec 7, 2023
@korniko98 korniko98 added the azure Issue related to an Azure service label Dec 28, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
addition New security issue or vulnerability azure Issue related to an Azure service
Projects
None yet
Development

No branches or pull requests

2 participants