QID 378483

Date Published: 2023-05-18

QID 378483: Azure Service Fabric Explorer Spoofing Vulnerability

Azure Service Fabric is Microsoft's platform-as-a-service (PaaS) and a container orchestrator solution used to build and deploy microservices-based cloud applications across a cluster of machines.

A Spoofing vulnerability exists in Service Fabric

Affected Versions:
Service Fabric 9.1 for Ubuntu prior to 9.1.1388.1

Service Fabric 9.1 for Windows prior to 9.1.1583.9590

QID Detection Logic:
This authenticated Unix QID detects vulnerable FabricHost package versions lesser than 9.0.1035.1

Successful exploitation may impact confidentiality, integrity and availability

  • CVSS V3 rated as Medium - 4.7 severity.
  • CVSS V2 rated as Critical - 9.7 severity.
  • Solution
    Customers are advised to refer to CVE-2023-23383 for updates pertaining to this vulnerability.

    CVEs related to QID 378483

    Software Advisories
    Advisory ID Software Component Link
    CVE-2023-23383 URL Logo msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2023-23383