wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
303 stars 61 forks source link

[Contribution] Add Azure HDInsight DoS and privesc #258

Open 0xdabbad00 opened 9 months ago

0xdabbad00 commented 9 months ago

Summary (give a brief description of the issue)

3 vulns were found by Orca in Azure HDInsight requiring authenticated access to the cluster, with two of them allowing privilege escalation and the 3rd just being DoS. This seems Low or Medium severity to me due to requiring authenticated access.

References (provide links to blogposts, etc.)

https://msrc.microsoft.com/blog/2023/12/microsoft-mitigates-three-vulnerabilities-in-azure-hdinsight/