Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2020-16904

Опубликовано: 13 окт. 2020
Источник: msrc
CVSS3: 5.3
EPSS Низкий

Описание

Azure Functions Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.

An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization.

This security update addresses the vulnerability by correctly validating access keys used to access HTTP Functions.

FAQ

How do I get the Azure Functions update?

Re-start your Azure Functions app to get the latest version with the security update.

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 86%
0.02759
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
nvd
больше 5 лет назад

<p>An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.</p> <p>An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization.</p> <p>This security update addresses the vulnerability by correctly validating access keys used to access HTTP Functions.</p>

CVSS3: 5.3
github
больше 3 лет назад

An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization.This security update addresses the vulnerability by correctly validating access keys used to access HTTP Functions., aka 'Azure Functions Elevation of Privilege Vulnerability'.

CVSS3: 9.8
fstec
больше 5 лет назад

Уязвимость службы Azure Functions операционной системы Windows, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 86%
0.02759
Низкий

5.3 Medium

CVSS3