PT-2020-4387 · Microsoft · Azure Functions

Published

2020-10-13

·

Updated

2023-12-31

·

CVE-2020-16904

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Azure Functions (affected versions not specified)
Description: The issue is related to an elevation of privilege vulnerability in the way Azure Functions validate access keys. An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization. The vulnerability is associated with insecure privilege management.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Incorrect Authorization

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2020-04900
CVE-2020-16904

Affected Products

Azure Functions