Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.
Metrics
Affected Vendors & Products
References
History
Wed, 05 Feb 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft azure Functions |
|
| CPEs | cpe:2.3:a:microsoft:azure_functions:-:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft azure Functions |
Tue, 10 Dec 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | ||
| Vendors & Products |
Microsoft
Microsoft azure Functions |
Tue, 26 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authentication for critical function in Microsoft Azure Functions allows an unauthorized attacker to elevate privileges over a network. | Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network. |
| Title | Microsoft Azure Functions Elevation of Privilege Vulnerability | Microsoft Azure PolicyWatch Elevation of Privilege Vulnerability |
| Metrics |
ssvc
|
Tue, 26 Nov 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authentication for critical function in Microsoft Azure Functions allows an unauthorized attacker to elevate privileges over a network. | |
| Title | Microsoft Azure Functions Elevation of Privilege Vulnerability | |
| First Time appeared |
Microsoft
Microsoft azure Functions |
|
| Weaknesses | CWE-306 | |
| CPEs | cpe:2.3:a:microsoft:azure_functions:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Microsoft
Microsoft azure Functions |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published: 2024-11-26T19:44:58.433Z
Updated: 2025-07-08T15:41:29.083Z
Reserved: 2024-10-11T20:57:49.188Z
Link: CVE-2024-49052
Updated: 2024-11-26T19:57:59.492Z
Status : Analyzed
Published: 2024-11-26T20:15:32.723
Modified: 2025-02-05T20:36:56.830
Link: CVE-2024-49052
No data.