{"containers":{"cna":{"title":"Azure Functions Elevation of Privilege Vulnerability","datePublic":"2020-10-13T07:00:00.000Z","affected":[{"vendor":"Microsoft","product":"Azure Functions","cpes":[],"platforms":["Unknown"],"versions":[{"version":"N/A","status":"affected"}]}],"descriptions":[{"value":"<p>An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.</p>\n<p>An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization.</p>\n<p>This security update addresses the vulnerability by correctly validating access keys used to access HTTP Functions.</p>","lang":"en-US"}],"problemTypes":[{"descriptions":[{"description":"Elevation of Privilege","lang":"en-US","type":"Impact"}]}],"providerMetadata":{"orgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","shortName":"microsoft","dateUpdated":"2023-12-31T19:19:47.896Z"},"references":[{"tags":["x_refsource_MISC"],"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16904"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en-US","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","baseSeverity":"MEDIUM","baseScore":5.3,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C"}}]},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-04T13:45:34.161Z"},"title":"CVE Program Container","references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16904"}]}]},"cveMetadata":{"assignerOrgId":"f38d906d-7342-40ea-92c1-6c4a2c6478c8","assignerShortName":"microsoft","cveId":"CVE-2020-16904","datePublished":"2020-10-16T22:17:42.000Z","dateReserved":"2020-08-04T00:00:00.000Z","dateUpdated":"2024-08-04T13:45:34.161Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}