An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization.This security update addresses the vulnerability by correctly validating access keys used to access HTTP Functions., aka 'Azure Functions Elevation of Privilege Vulnerability'.
References
Link | Resource |
---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16904 | Patch Vendor Advisory |
Configurations
Information
Published : 2020-10-16 16:15
Updated : 2021-07-21 04:39
NVD link : CVE-2020-16904
Mitre link : CVE-2020-16904
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
microsoft
- azure_functions