Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Contribution] Add Nitesh Surana Azure ZDI findings #283

Open
ramimac opened this issue Mar 19, 2024 · 0 comments
Open

[Contribution] Add Nitesh Surana Azure ZDI findings #283

ramimac opened this issue Mar 19, 2024 · 0 comments
Labels
addition New security issue or vulnerability azure Issue related to an Azure service

Comments

@ramimac
Copy link
Contributor

ramimac commented Mar 19, 2024

Summary (give a brief description of the issue)

ZDI-24-208 (9.8) Microsoft Azure MCR VSTS CLI vstscli Uncontrolled Search Path Element Remote Code Execution Vulnerability
ZDI-23-1588 (8.8) Microsoft Azure US Accelarators Synapse SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability
ZDI-23-1056 (4.4) (0Day) Microsoft Azure Machine Learning Compute Instance certificate Exposure of Resource to Wrong Sphere Information Disclosure Vulnerability
ZDI-23-880 (5.5) Microsoft Azure Machine Learning Service DSIMountAgent Missing Authentication Information Disclosure Vulnerability
ZDI-23-380 (6.5) Microsoft Azure Machine Learning Service DSIMountAgent Missing Authentication Information Disclosure Vulnerability
ZDI-23-161 (6.5) Microsoft Azure Machine Learning Service Cleartext Storage of Credentials Information Disclosure Vulnerability
ZDI-23-097 (6.8) Microsoft Azure Machine Learning Service JWT Cleartext Storage of Credentials Information Disclosure Vulnerability
ZDI-23-096 (6.5) Microsoft Azure Machine Learning Service Cleartext Storage of Credentials Information Disclosure Vulnerability
ZDI-23-095 (6.5) Microsoft Azure Machine Learning Service Cleartext Storage of Credentials Information Disclosure Vulnerability

@ramimac ramimac added the addition New security issue or vulnerability label Mar 19, 2024
@korniko98 korniko98 added the azure Issue related to an Azure service label Apr 28, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
addition New security issue or vulnerability azure Issue related to an Azure service
Projects
None yet
Development

No branches or pull requests

2 participants