First published: Fri Oct 16 2020(Updated: )
<p>An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.</p> <p>An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization.</p> <p>This security update addresses the vulnerability by correctly validating access keys used to access HTTP Functions.</p>
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Azure Functions |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-16904 is considered a medium severity vulnerability due to its potential for unauthorized access.
To remediate CVE-2020-16904, ensure that you are using the latest version of Azure Functions that includes the security updates.
Any organization utilizing Azure Functions could be impacted by CVE-2020-16904 if they do not properly secure their access keys.
CVE-2020-16904 allows an unauthenticated attacker to invoke HTTP Functions without proper authorization.
CVE-2020-16904 is a specific vulnerability related to access key validation and may not be commonly encountered if proper security practices are followed.