March 23, 2023, midnight |

The Open Cloud Vulnerability & Security Issue Database www.cloudvulndb.org

Undocumented APIs used by the Azure Function Apps Portal could have allowed an attacker with existing
access to a Reader role on a Function App to escalate their privileges and gain write permissions
through arbitrary file reads on Function App containers. For Windows containers, this would only
grant an attacker the ability to extract ASP.NET encryption keys (the impact of which remains unclear),
but for Linux containers it would have allowed an attacker to read environmental variables containing
information that …

access apis app app containers apps asp azure containers escalation extract file function grant .net permissions portal privilege privilege escalation privileges reader role windows

Cyber Software Engineering, Senior Advisor

@ Peraton | Annapolis Junction, MD, United States

Cybersecurity Architect, Lead (NJUS)

@ NetJets | Columbus, OH, US, 43219

Security Operations Analyst

@ Commonwealth Financial Network | Waltham, MA, United States

Penetration Tester – Senior Associate - Cybersecurity

@ JPMorgan Chase & Co. | Buenos Aires, Argentina

Manager - Endpoint Security

@ Novo Nordisk | Bengaluru, Karnataka, IN

Senior Officer, Identity Access Management Administrator, Group Information Security (Contract)

@ UOB | Singapore (City Area), SG, 048624