CVE-2023-35625HighCVSS 4.7

Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability

Published
December 12, 2023
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

According to the CVSS metric, the attack complexity is high (AC:H). What does this mean for this vulnerability? The vulnerability enables data leakage only when a user's script is improperly used and triggers specific errors. The conditions required for triggering the error are not easily met making the complexity high.

What type of information could be disclosed by this vulnerability? The Azure Machine Learning (ML) training data associated with user accounts will be disclosed. This data primarily consists of information used for ML model training purposes within the Azure ML system.

🎯 Affected products1

  • Azure Machine Learning SDK

✅ Remediation

KBRelease Notes (Security Update) — fixed build 1.5.0

🔗 References (2)