Description
Azure Site Recovery Elevation of Privilege Vulnerability
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:HExploitability: 1.2 | Impact: 5.2Attack Vector: Network
Complexity: Low
Privileges: High
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: High
Availability: High
Affected Packages2 packages
🔴Vulnerability Details
4GHSAAuthlib has algorithm confusion with asymmetric public keys↗2024-06-09 ▶ GHSApython-jose algorithm confusion with OpenSSH ECDSA keys↗2024-04-26 ▶ GHSAGHSA-v5f2-6j8h-cj5q: Azure Site Recovery Elevation of Privilege Vulnerability↗2022-07-13 ▶ CVEListAzure Site Recovery Elevation of Privilege Vulnerability↗2022-07-12 ▶ 📋Vendor Advisories
2Red Hatpython-jose: algorithm confusion with OpenSSH ECDSA keys and other key formats↗2024-04-26 ▶ MicrosoftAzure Site Recovery Elevation of Privilege Vulnerability↗2022-07-12 ▶