Lucene search

K
msrcMicrosoft Security Response CenterMSRC:CB72EBE1E9960921B5DAEB5C282E719D
HistoryOct 19, 2022 - 7:00 a.m.

Awareness and guidance related to potential Service Fabric Explorer (SFX) v1 web client risk

2022-10-1907:00:00
Microsoft Security Response Center
link
8
microsoft
service fabric explorer
cross-site scripting
vulnerability
sfxv1.

0.001 Low

EPSS

Percentile

21.9%

Summary Summary Microsoft was recently made aware of a Cross-Site Scripting (XSS) vulnerability (CVE-2022-35829), that under limited circumstances, affects older versions of Service Fabric Explorer (SFX). The current default SFX web client (SFXv2) is not vulnerable to this attack. However, customers can manually switch from the default web client (SFXv2) to an older vulnerable SFX web client version (SFXv1).

0.001 Low

EPSS

Percentile

21.9%