Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2022-30187

Опубликовано: 12 июл. 2022
Источник: msrc
CVSS3: 4.7
EPSS Низкий

Описание

Azure Storage Library Information Disclosure Vulnerability

FAQ

What is CBC padding in storage SDK?

Azure Storage .NET, Java, and Python SDKs use cipher block chaining (CBC mode) for client-side encryption. This client-side encryption is used by very small set of customers, who encrypt their data on the client with a customer-managed key that is maintained in Azure Key Vault or another key store before uploading to Azure Storage.

What type of information could be disclosed by this vulnerability?

An attacker who successfully exploited this vulnerability could decrypt data on the client side and disclose the content of the file or blob.

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?

Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.

Обновления

ПродуктСтатьяОбновление
Azure Storage Blobs client library for .NET
Azure Storage Blobs client library for Python
Azure Storage Queues client library for .NET
Azure Storage Blobs client library for Java
Azure Storage Queues client library for Python

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

Older Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 56%
0.00336
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
больше 3 лет назад

Azure Storage Library Information Disclosure Vulnerability

redhat
больше 3 лет назад

Azure Storage Library Information Disclosure Vulnerability

CVSS3: 4.7
nvd
больше 3 лет назад

Azure Storage Library Information Disclosure Vulnerability

suse-cvrf
больше 1 года назад

Security update for python-azure-core, python-azure-storage-blob, python-azure-storage-queue, python-typing, python-typing_extensions

suse-cvrf
около 2 лет назад

Security update for python-azure-storage-queue

EPSS

Процентиль: 56%
0.00336
Низкий

4.7 Medium

CVSS3