Описание
Azure HDInsight Ambari Elevation of Privilege Vulnerability
Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
FAQ
What privileges an attacker could gain with a successful exploitation?
An attacker with the Service Operator role in Azure HDInsight Ambari can exploit a command injection flaw in the HDFS REBALANCEHDFS custom command to execute arbitrary system commands as the hdfs user on the NameNode.
What action should customers take to address this vulnerability?
Customers should recreate affected Azure HDInsight clusters so they are provisioned with the updated image. The fix is included in the June 29, 2026 Azure HDInsight release, image 2606012120, and later images. For instructions, see Set up clusters in HDInsight with Hadoop, Spark, and Kafka.
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
7.2 High
CVSS3
Связанные уязвимости
Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
Improper neutralization of special elements used in an os command ('os command injection') in Azure HDInsights allows an authorized attacker to elevate privileges over a network.
EPSS
7.2 High
CVSS3