March 14, 2023, midnight |

The Open Cloud Vulnerability & Security Issue Database www.cloudvulndb.org

Azure Service Fabric Explorer (SFX) was affected by an XSS vulnerability that
could have allowed a malicious script to be reflected off a web application.
After a potential victim clicked on a crafted malicious URL, the attacker could
remotely toggle the ‘Cluster’ Event Type setting under the Events tab. This could
lead to unauthenticated remote code execution on a container hosted on a Service Fabric node.

application attacker azure azure service azure service fabric explorer cluster code code execution event events explorer fabrixss malicious remote code remote code execution script service service fabric sfx super super fabrixss tab unauthenticated under url victim vulnerability web web application xss

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC