Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[Contribution] Add Azure Machine Learning Compute Instance Information Disclosure Vulnerability (CVE-2023-23382) #200

Open
korniko98 opened this issue Jul 31, 2023 · 0 comments
Labels
addition New security issue or vulnerability azure Issue related to an Azure service

Comments

@korniko98
Copy link
Collaborator

korniko98 commented Jul 31, 2023

Summary (give a brief description of the issue)

An attacker that successfully exploited this vulnerability could recover any data that is put in the system logs on the Compute Instance including cleartext passwords.

References (provide links to blogposts, etc.)

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2023-23382
https://twitter.com/_niteshsurana/status/1625583368690888705
https://www.blackhat.com/us-23/briefings/schedule/#uncovering-azures-silent-threats-a-journey-into-cloud-vulnerabilities-33073

@korniko98 korniko98 added the addition New security issue or vulnerability label Jul 31, 2023
@korniko98 korniko98 added the azure Issue related to an Azure service label Sep 24, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
addition New security issue or vulnerability azure Issue related to an Azure service
Projects
None yet
Development

No branches or pull requests

1 participant