PT-2020-4387 · Microsoft · Azure Functions
Published
2020-10-13
·
Updated
2023-12-31
·
CVE-2020-16904
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Azure Functions (affected versions not specified)
Description:
The issue is related to an elevation of privilege vulnerability in the way Azure Functions validate access keys. An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization. The vulnerability is associated with insecure privilege management.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
LPE
Incorrect Authorization
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Azure Functions