CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Improper Authorization in Azure Automation allows an authorized attacker to elevate privileges over a network. |
1Microsoft 8Azure Automation Azure Automation Update ManagementAzure Security Center+5 moreDec 27, 2024 Mar 12, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability |
1Microsoft 4Azure Active Directory Azure Active Site RecoveryAzure Automation+1 moreFeb 24, 2026 Nov 24, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal...Show more |
An elevation of privilege vulnerability exists in Azure Automation "RunAs account" runbooks for users with contributor role, aka 'Azure Automation Elevation of Privilege Vulnerability'. |