CVE-2022-23256HighCVSS 8.1

Azure Data Explorer Spoofing Vulnerability

Published
February 8, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of confidentiality (C:H)? What does that mean for this vulnerability? This vulnerability discloses a user's JSON web token to the attacker.

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? The user would have to click on a specially crafted URL to be compromised by the attacker.

How do I get the security update for Azure Data Explorer? You need to restart the Kusto.Explorer application. The update will be automatically downloaded. Where can I find information about the update? Release notes for the update are available in the application menu under Help->What’s new, under the applicable Version.

According to the CVSS metric, successful exploitation of this vulnerability could lead to total loss of integrity (I:H)? What does that mean for this vulnerability? The compromised JSON web token can be used to compromise accounts and modify account information.

🎯 Affected products1

  • Azure Data Explorer

🔗 References (1)