Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-v3gf-q256-843h

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 5.3

Описание

An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization.This security update addresses the vulnerability by correctly validating access keys used to access HTTP Functions., aka 'Azure Functions Elevation of Privilege Vulnerability'.

An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization.This security update addresses the vulnerability by correctly validating access keys used to access HTTP Functions., aka 'Azure Functions Elevation of Privilege Vulnerability'.

EPSS

Процентиль: 86%
0.02759
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-269
CWE-863

Связанные уязвимости

CVSS3: 5.3
nvd
больше 5 лет назад

<p>An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.</p> <p>An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization.</p> <p>This security update addresses the vulnerability by correctly validating access keys used to access HTTP Functions.</p>

msrc
больше 5 лет назад

Azure Functions Elevation of Privilege Vulnerability

CVSS3: 9.8
fstec
больше 5 лет назад

Уязвимость службы Azure Functions операционной системы Windows, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 86%
0.02759
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-269
CWE-863