Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2023-36052

Опубликовано: 14 нояб. 2023
Источник: msrc
CVSS3: 8.6
EPSS Низкий

Описание

Azure CLI REST Command Information Disclosure Vulnerability

FAQ

What type of information could be disclosed by this vulnerability?

An attacker that successfully exploited this vulnerability could recover plaintext passwords and usernames from log files created by the affected CLI commands and published by Azure DevOps and/or GitHub Actions.

According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?

An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.

How could an attacker exploit this vulnerability?

An unauthenticated attacker can search and discover credentials contained in log files which have been stored in open-source repositories.

Where can I find more information?

Please see the MSRC Blog Post relating to this vulnerability here: Microsoft guidance regarding credentials leaked to Github Actions logs through Azure CLI.

What actions do customers need to take to protect themselves from this vulnerability?

Customers using the affected CLI commands must update their Azure CLI version to 2.53.1 or above to be protected against the risks of this vulnerability. This also applies to customers with log files created by using these commands through Azure DevOps and/or GitHub Actions.

Обновления

ПродуктСтатьяОбновление
az webapp config appsettings set
az webapp config appsettings delete
az logicapp config appsettings set
az logicapp config appsettings delete
az functionapp config appsettings set
az functionapp config appsettings delete
az staticwebapp appsettings set
az staticwebapp appsettings delete

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 60%
0.00396
Низкий

8.6 High

CVSS3

Связанные уязвимости

CVSS3: 8.6
nvd
около 2 лет назад

Azure CLI REST Command Information Disclosure Vulnerability

CVSS3: 8.6
github
около 2 лет назад

Azure CLI REST Command Information Disclosure Vulnerability

CVSS3: 8.6
fstec
около 2 лет назад

Уязвимость интерфейса командной строки (CLI) платформы Microsoft Azure, позволяющая нарушителю получить доступ к учетным данным

EPSS

Процентиль: 60%
0.00396
Низкий

8.6 High

CVSS3