Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:44030
HistoryOct 27, 2023 - 3:56 p.m.

Remote Code Execution (RCE)

2023-10-2715:56:11
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
vulnerability
rce
azure.identity
property sanitization
os-level command
sdk

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.004

Percentile

74.9%

Azure.Identity is vulnerable to Remote Code Execution. The vulnerability is due to improper property sanitization, which allows an attacker to pass a specially crafted OS-level command to a specific SDK property which can result in Remote Code Execution. The vulnerability exists in the DefaultAzureCredential, AzureCliCredential, AzureDeveloperCliCredential and AzurePowerShellCredential types.

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.5

Confidence

High

EPSS

0.004

Percentile

74.9%