PT-2021-1676 · Microsoft · Azure Active Directory

Published

2021-01-12

·

Updated

2024-10-08

·

CVE-2021-1677

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Azure Active Directory (affected versions not specified)
Description The issue is related to an information disclosure vulnerability in the Azure Active Directory Pod Identity service. It may allow an attacker to gain unauthorized access to protected information using a specially crafted IMDS request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Spoofing

Authentication Bypass by Spoofing

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2021-00332
CVE-2021-1677

Affected Products

Azure Active Directory