CVE-2022-26907HighCVSS 5.3

Azure SDK for .NET Information Disclosure Vulnerability

Published
April 12, 2022
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

What type of information could be disclosed by this vulnerability? This vulnerability could disclose sensitive information in exception body, which might include user access tokens.

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to have access to the location where the application that is using the SDK is storing the exception (for example, event logs).

🎯 Affected products1

  • Azure SDK for .Net

✅ Remediation

KBRelease Notes (Security Update) — fixed build 2.3.24

🔗 References (2)