First published: Tue Oct 10 2023(Updated: )
Azure Identity SDK Remote Code Execution Vulnerability
Credit: secure@microsoft.com secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Azure Identity SDK for Python | ||
Microsoft Azure Identity SDK for JavaScript | ||
Microsoft Azure Identity SDK for .NET | ||
Microsoft Azure Identity SDK for Java | ||
Microsoft Azure Identity Sdk | <1.10.2 | |
Microsoft Azure Identity Sdk | <1.10.2 | |
Microsoft Azure Identity Sdk | <1.14.1 | |
Microsoft Azure Identity Sdk | <3.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-36415 is a remote code execution vulnerability found in the Azure Identity SDK.
The Azure Identity SDK for Java, Python, JavaScript, and .NET are affected by CVE-2023-36415.
CVE-2023-36415 has a severity value of 8.8, which is considered high.
To fix CVE-2023-36415 in Azure Identity SDK for Java, you can follow the remediation steps provided in the Microsoft Azure SDK for Java repository.
You can find more information about CVE-2023-36415 in the Microsoft Security Response Center's update guide.