| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A spoofing vulnerability exists in Azure DevOps Server when it improperly handles requests to authorize applications, resulting in a cross-site request forgery. An attacker who successfully exploited this vulnerability could bypass OAuth protections and register an application on behalf of the targeted user.
To exploit this vulnerability, an attacker would need to create a page specifically designed to cause a cross-site request. The attacker would then need to convince a targeted user to click a link to the malicious page.
The update addresses the vulnerability by modifying how Azure DevOps Server protects application registration requests. |
| Azure Storage Mover Remote Code Execution Vulnerability |
| Azure Stack Hub Spoofing Vulnerability |
| Azure Connected Machine Agent Elevation of Privilege Vulnerability |
| Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability |
| Azure Data Studio Elevation of Privilege Vulnerability |
| Azure SDK Spoofing Vulnerability |
| Azure CycleCloud Elevation of Privilege Vulnerability |
| Azure Identity Library for .NET Information Disclosure Vulnerability |
| Azure Monitor Agent Elevation of Privilege Vulnerability |
| Azure Arc-enabled Kubernetes Extension Cluster-Scope Elevation of Privilege Vulnerability |
| Microsoft Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability |
| Azure Private 5G Core Denial of Service Vulnerability |
| Azure AI Search Information Disclosure Vulnerability |
| Azure Compute Gallery Elevation of Privilege Vulnerability |
| Azure Migrate Remote Code Execution Vulnerability |
| Azure Monitor Agent Elevation of Privilege Vulnerability |
| Azure Migrate Cross-Site Scripting Vulnerability |
| Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting machine runs an Azure CLI command where parameter values have been provided by an external source. The vulnerability is only applicable when the Azure CLI command is run on a Windows machine and with any version of PowerShell and when the parameter value contains the `&` or `|` symbols. If any of these prerequisites are not met, this vulnerability is not applicable. Users should upgrade to version 2.40.0 or greater to receive a a mitigation for the vulnerability. |
| Azure RTOS USBX is a USB host, device, and on-the-go (OTG) embedded stack, that is fully integrated with Azure RTOS ThreadX. Prior to version 6.1.12, the USB DFU UPLOAD functionality may be utilized to introduce a buffer overflow resulting in overwrite of memory contents. In particular cases this may allow an attacker to bypass security features or execute arbitrary code. The implementation of `ux_device_class_dfu_control_request` function prevents buffer overflow during handling of DFU UPLOAD command when current state is `UX_SYSTEM_DFU_STATE_DFU_IDLE`. This issue has been patched, please upgrade to version 6.1.12. As a workaround, add the `UPLOAD_LENGTH` check in all possible states. |