CVE-2023-36415: Azure Identity SDK Remote Code Execution Vulnerability
Published Oct 10, 2023
·Updated
Azure Identity SDK Remote Code Execution Vulnerability
Affected Software
8 affected componentsFixes available
Microsoft Azure Identity Sdk .net<1.10.2
Microsoft Azure Identity Sdk Java<1.10.2
Microsoft Azure Identity Sdk Python<1.14.1
Microsoft Azure Identity Sdk Javascript<3.3.1
Microsoft Azure Identity SDK for Java
Microsoft Azure Identity SDK for JavaScript
Microsoft Azure Identity SDK for Python
Microsoft Azure Identity SDK for .NET
Remediation
Event History
Oct 10, 2023
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·05:08 PM
Data Sourced
via MITRE·05:08 PM
DescriptionSeverity
Frequently Asked Questions
1
What is CVE-2023-36415?
CVE-2023-36415 is a remote code execution vulnerability found in the Azure Identity SDK.
2
Which software is affected by CVE-2023-36415?
The Azure Identity SDK for Java, Python, JavaScript, and .NET are affected by CVE-2023-36415.
3
What is the severity of CVE-2023-36415?
CVE-2023-36415 has a severity value of 8.8, which is considered high.
4
How can I fix CVE-2023-36415 in Azure Identity SDK for Java?
To fix CVE-2023-36415 in Azure Identity SDK for Java, you can follow the remediation steps provided in the Microsoft Azure SDK for Java repository.
5
Where can I find more information about CVE-2023-36415?
You can find more information about CVE-2023-36415 in the Microsoft Security Response Center's update guide.