Microsoft Azure Automation vulnerabilities

4 known vulnerabilities affecting microsoft/azure_automation.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2025-29827HIGHCVSS 8.8v-2025-05-08
CVE-2025-29827 [CRITICAL] CWE-285 CVE-2025-29827: Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.
cvelistv5nvd
CVE-2024-21330HIGHCVSS 7.8≥ 1.0.0, < OMS Agent for Linux GA 1.19.02024-03-12
CVE-2024-21330 [HIGH] CWE-122 CVE-2024-21330: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
cvelistv5nvd
CVE-2021-42306MEDIUMCVSS 6.5fixed in 2021-10-15≥ 1.0.0, < publication2021-11-24
CVE-2021-42306 [HIGH] CWE-522 CVE-2021-42306: An information disclosure vulnerability manifests when a user or an application uploads unprotected An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a user or service in the tenant with application read access to read the private
cvelistv5nvd
CVE-2019-0962MEDIUMCVSS 4.9vN/A2019-07-15
CVE-2019-0962 [MEDIUM] CVE-2019-0962: An elevation of privilege vulnerability exists in Azure Automation "RunAs account" runbooks for user An elevation of privilege vulnerability exists in Azure Automation "RunAs account" runbooks for users with contributor role, aka 'Azure Automation Elevation of Privilege Vulnerability'.
cvelistv5nvd