ZDI-CAN-22282: ZDI-23-1588: Microsoft Azure US Accelarators Synapse SAS Token Incorrect Permission Assignment Authentication Bypass Vulnerability
Published Nov 6, 2023
·Updated
This vulnerability allows remote attackers to bypass authentication on Microsoft Azure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.
Affected Software
1 affected component
Microsoft Azure
Event History
Nov 6, 2023
Advisory Published
06:00 AM
Data Sourced
06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-22282?
The severity of ZDI-CAN-22282 is rated 8.8 on the CVSS scale, indicating a high risk level.
2
How do I fix ZDI-CAN-22282?
To fix ZDI-CAN-22282, apply the latest security updates provided by Microsoft for Azure.
3
What does ZDI-CAN-22282 exploit?
ZDI-CAN-22282 allows remote attackers to bypass authentication on Microsoft Azure.
4
Is authentication required to exploit ZDI-CAN-22282?
No, authentication is not required to exploit ZDI-CAN-22282.
5
Who is affected by ZDI-CAN-22282?
Users and organizations utilizing Microsoft Azure are affected by ZDI-CAN-22282.