Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-35255

Опубликовано: 01 июл. 2024
Источник: redhat
CVSS3: 5.5

Описание

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

A flaw was found in Microsoft's Azure Identity Libraries and the Microsoft Authentication Library (MSAL). The flaw arises from a race condition—a scenario where the timing of events leads to unexpected behavior—during concurrent operations on shared resources. This can result in privilege escalation, allowing attackers to gain unauthorized access to sensitive information. The vulnerability affects multiple versions of these libraries across various programming languages, including Java, .NET, Node.js, Python, JavaScript, C++, and Go. Microsoft has addressed this issue by releasing updated versions of the affected libraries. Users are strongly advised to upgrade to these patched versions to mitigate potential security risks.

Отчет

Red Hat build of Apache Camel for Spring boot is not affected as 4.4.1 was released containing a fixed version of the Azure Identity Library.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Ansible Automation Platform 2aap-cloud-metrics-collector-containerWill not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-dellemc-openmanage-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-minimal-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-supported-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/platform-resource-runner-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ansible-builder-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ee-cloud-services-rhel9Not affected
Red Hat build of Apache Camel for Spring Boot 3com.azure/azure-identityWill not fix
Red Hat build of Apache Camel for Spring Boot 4com.azure/azure-identityNot affected
Red Hat build of Quarkuscom.azure/azure-identityWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=2295081azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
больше 1 года назад

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

CVSS3: 5.5
msrc
больше 1 года назад

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

suse-cvrf
11 месяцев назад

Security update for python-azure-identity

suse-cvrf
больше 1 года назад

Security update for python-azure-identity

CVSS3: 5.5
github
больше 1 года назад

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

5.5 Medium

CVSS3