Lucene search

K
mscveMicrosoftMS:CVE-2022-39327
HistoryNov 08, 2022 - 8:00 a.m.

GitHub: CVE-2022-39327 Improper Control of Generation of Code ('Code Injection') in Azure CLI

2022-11-0808:00:00
Microsoft
msrc.microsoft.com
64
github
cve-2022-39327
azure
cli
code injection
microsoft

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.004

Percentile

75.1%

Affected configurations

Vulners
Node
microsoftazure_command-line_interfaceRange<2.42.0
VendorProductVersionCPE
microsoftazure_command-line_interface*cpe:2.3:a:microsoft:azure_command-line_interface:*:*:*:*:*:*:*:*

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS

0.004

Percentile

75.1%