Описание
Azure SDK for .NET Information Disclosure Vulnerability
FAQ
What type of information could be disclosed by this vulnerability?
This vulnerability could disclose sensitive information in exception body, which might include user access tokens.
According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to have access to the location where the application that is using the SDK is storing the exception (for example, event logs).
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
Older Software Release
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
Azure SDK for .NET Information Disclosure Vulnerability
Azure SDK for .NET Information Disclosure Vulnerability.
Уязвимость программного пакета для разработки программного обеспечения Azure SDK для .NET, связанная с недостаточной защитой регистрационных данных, позволяющая нарушителю получить доступ к конфиденциальным данным
EPSS
5.3 Medium
CVSS3