PT-2021-2729 · Microsoft · Ms-Rest-Nodeauth

Published

2021-03-22

·

Updated

2023-12-29

·

CVE-2021-28458

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ms-rest-nodeauth library (affected versions not specified)
Description The issue is related to the implementation of the execAz() function in the authentication library for Azure services, which fails to neutralize special elements used in operating system commands. This could allow an attacker to elevate their privileges using a specially crafted AzureCliCredentials.setDefaultSubscription call.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

OS Command Injection

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2021-02263
CVE-2021-28458
GHSA-QPFW-4M9X-RXX8

Affected Products

Ms-Rest-Nodeauth