Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-35255

Опубликовано: 01 июл. 2024
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

A flaw was found in Microsoft's Azure Identity Libraries and the Microsoft Authentication Library (MSAL). The flaw arises from a race condition—a scenario where the timing of events leads to unexpected behavior—during concurrent operations on shared resources. This can result in privilege escalation, allowing attackers to gain unauthorized access to sensitive information. The vulnerability affects multiple versions of these libraries across various programming languages, including Java, .NET, Node.js, Python, JavaScript, C++, and Go. Microsoft has addressed this issue by releasing updated versions of the affected libraries. Users are strongly advised to upgrade to these patched versions to mitigate potential security risks.

Отчет

Red Hat build of Apache Camel for Spring boot is not affected as 4.4.1 was released containing a fixed version of the Azure Identity Library.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence-tech-preview/vulnerability-analysis-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-cpu-rhel9Not affected
Red Hat AI Inference Serverrhaiis/vllm-tpu-rhel9Not affected
Red Hat Ansible Automation Platform 2aap-cloud-metrics-collector-containerWill not fix
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ansible-builder-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-dellemc-openmanage-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-24/ee-minimal-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ee-cloud-services-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/ee-supported-rhel8Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/platform-resource-runner-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-362
https://bugzilla.redhat.com/show_bug.cgi?id=2295081azure-identity: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/Azure/azure-sdk-for-go/sdk/azidentity

EPSS

Процентиль: 55%
0.0083
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
nvd
около 2 лет назад

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

CVSS3: 5.5
msrc
около 2 лет назад

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

suse-cvrf
больше 1 года назад

Security update for python-azure-identity

suse-cvrf
почти 2 года назад

Security update for python-azure-identity

CVSS3: 5.5
github
около 2 лет назад

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

EPSS

Процентиль: 55%
0.0083
Низкий

5.5 Medium

CVSS3