Vulnerabilities (CVE)

Filtered by vendor Microsoft Subscribe
Filtered by product Azure Functions
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-16904 1 Microsoft 1 Azure Functions 2024-11-21 7.5 HIGH 5.3 MEDIUM
<p>An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.</p> <p>An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization.</p> <p>This security update addresses the vulnerability by correctly validating access keys used to access HTTP Functions.</p>
CVE-2024-38204 1 Microsoft 1 Azure Functions 2024-11-08 N/A 6.5 MEDIUM
Improper Access Control in Imagine Cup allows an authorized attacker to elevate privileges over a network.