CVE-2020-16904

<p>An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.</p> <p>An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization.</p> <p>This security update addresses the vulnerability by correctly validating access keys used to access HTTP Functions.</p>
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:azure_functions:-:*:*:*:*:*:*:*

History

31 Dec 2023, 20:15

Type Values Removed Values Added
Summary An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization.This security update addresses the vulnerability by correctly validating access keys used to access HTTP Functions., aka 'Azure Functions Elevation of Privilege Vulnerability'. <p>An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.</p> <p>An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization.</p> <p>This security update addresses the vulnerability by correctly validating access keys used to access HTTP Functions.</p>
CVSS v2 : 7.5
v3 : 9.8
v2 : 7.5
v3 : 5.3

Information

Published : 2020-10-16 23:15

Updated : 2024-02-28 18:08


NVD link : CVE-2020-16904

Mitre link : CVE-2020-16904

CVE.ORG link : CVE-2020-16904


JSON object : View

Products Affected

microsoft

  • azure_functions
CWE
CWE-863

Incorrect Authorization