Описание
Azure Logic Apps Elevation of Privilege Vulnerability
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
FAQ
What do customers do to protect themselves from the vulnerability?
Customers will be notified via Azure Service Health notification if they are impacted by this vulnerability. These alerts will include specific mitigation guidance and required actions for affected Azure Logic Apps resources.
Customers who have received an Azure Service Health notification for this issue can reference** Tracking ID:** 1P8-C0G in the Azure portal to review the applicable guidance and required remediation steps.
The Security Updates table for this CVE will be updated as additional information becomes available.
Additionally, customers who have subscribed to the Security Update Guide will be notified when this CVE is revised to reflect updated guidance or mitigation details. If you wish to be notified when updates are released, we recommend registering for security notifications to stay informed of content changes.
Возможность эксплуатации
Publicly Disclosed
Exploited
Latest Software Release
EPSS
9.9 Critical
CVSS3
Связанные уязвимости
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
Improper access control in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
Уязвимость облачной платформы создания и запуска автоматизированных рабочих процессов Azure Logic App операционных систем Windows, позволяющая нарушителю повысить привилегии
EPSS
9.9 Critical
CVSS3