Описание
Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability
FAQ
According to the CVSS metric, the attack complexity is high (AC:H). What does this mean for this vulnerability?
The vulnerability enables data leakage only when a user's script is improperly used and triggers specific errors. The conditions required for triggering the error are not easily met making the complexity high.
What type of information could be disclosed by this vulnerability?
The Azure Machine Learning (ML) training data associated with user accounts will be disclosed. This data primarily consists of information used for ML model training purposes within the Azure ML system.
Обновления
| Продукт | Статья | Обновление |
|---|---|---|
| Azure Machine Learning SDK |
Показывать по
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
DOS
EPSS
4.7 Medium
CVSS3
Связанные уязвимости
Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability
Уязвимость программного средства для работы с алгоритмами машинного обучения Azure Machine Learning, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить несанкционированный доступ к устройству
EPSS
4.7 Medium
CVSS3