Oct. 11, 2022, midnight |

The Open Cloud Vulnerability & Security Issue Database www.cloudvulndb.org

Service Fabric Explorer (SFX) is a tool for inspecting and managing Azure Service Fabric clusters.
An attacker with existing access to a "Deployer" type user with CreateComposeDeployment permissions
in a given cluster could create a malicious application with a specially-crafted name. This would
lead to client-side template injection (CSTI) and storing a malicious XSS payload in a dashboard
shared between users of the same cluster. If a victim user with administrative permissions logged
into the compromised SFX dashboard and clicked …

fabrixss

SOC 2 Manager, Audit and Certification

@ Deloitte | US and CA Multiple Locations

Information Security Engineers

@ D. E. Shaw Research | New York City

Information Security Manager & ISSO

@ Federal Reserve System | Minneapolis, MN

Forensic Lead

@ Arete | Hyderabad

Lead Security Risk Analyst (GRC)

@ Justworks, Inc. | New York City

Consultant Senior en Gestion de Crise Cyber et Continuité d’Activité H/F

@ Hifield | Sèvres, France