Filtered by vendor Microsoft Subscriptions
Filtered by product Azure Functions Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-49052 1 Microsoft 1 Azure Functions 2025-02-05 8.2 High
Missing authentication for critical function in Microsoft Azure PolicyWatch allows an unauthorized attacker to elevate privileges over a network.
CVE-2024-38204 1 Microsoft 1 Azure Functions 2025-01-29 7.5 High
Improper access control in Imagine Cup allows an authorized attacker to elevate privileges over a network.
CVE-2020-16904 1 Microsoft 1 Azure Functions 2024-11-21 5.3 Medium
<p>An elevation of privilege vulnerability exists in the way Azure Functions validate access keys.</p> <p>An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization.</p> <p>This security update addresses the vulnerability by correctly validating access keys used to access HTTP Functions.</p>