Lucene search

K
msrcMicrosoft Security Response CenterMSRC:E28798D2C5A81C4EF9C5F19F79EA0269
HistoryJul 18, 2022 - 7:00 a.m.

Mitigation for Azure Storage SDK Client-Side Encryption Padding Oracle Vulnerability

2022-07-1807:00:00
Microsoft Security Response Center
link
21

0.0005 Low

EPSS

Percentile

18.0%

Summary Summary Google informed Microsoft under Coordinated Vulnerability Disclosure (CVD) of a padding oracle vulnerability that may affect customers using Azure Storage SDK (for Python, .NET, Java) client-side encryption (CVE-2022-30187). To mitigate this vulnerability, we released a new General Availability (GA) version of the Azure Storage SDK client-side encryption feature (v2) on July 12, 2022.

0.0005 Low

EPSS

Percentile

18.0%