-
Notifications
You must be signed in to change notification settings - Fork 2.5k
Description
Vulnerable Library - azure-identity-1.11.4.jar
This module contains client library for Microsoft Azure Identity.
Library home page: https://github.com/Azure/azure-sdk-for-java
Path to dependency file: /plugins/repository-azure/build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.azure/azure-identity/1.11.4/59b5ce48888f638b80d85ef5aa0e22a265d3dc89/azure-identity-1.11.4.jar
Found in HEAD commit: 45e73c43e36926a8a03b094ec1ea254f5de91beb
Vulnerabilities
| CVE | Severity | Dependency | Type | Fixed in (azure-identity version) | Remediation Possible** | |
|---|---|---|---|---|---|---|
| CVE-2024-35255 | 5.5 | azure-identity-1.11.4.jar | Direct | 1.12.2 | ✅ |
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2024-35255
Vulnerable Library - azure-identity-1.11.4.jar
This module contains client library for Microsoft Azure Identity.
Library home page: https://github.com/Azure/azure-sdk-for-java
Path to dependency file: /plugins/repository-azure/build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.azure/azure-identity/1.11.4/59b5ce48888f638b80d85ef5aa0e22a265d3dc89/azure-identity-1.11.4.jar
Dependency Hierarchy:
- ❌ azure-identity-1.11.4.jar (Vulnerable Library)
Found in HEAD commit: 45e73c43e36926a8a03b094ec1ea254f5de91beb
Found in base branch: main
Vulnerability Details
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
Publish Date: 2024-06-11
URL: CVE-2024-35255
CVSS 3 Score Details (5.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Local
- Attack Complexity: Low
- Privileges Required: Low
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: High
- Integrity Impact: None
- Availability Impact: None
Suggested Fix
Type: Upgrade version
Origin: GHSA-m5vv-6r4h-3vj9
Release Date: 2024-06-11
Fix Resolution: 1.12.2
⛑️ Automatic Remediation will be attempted for this issue.
⛑️Automatic Remediation will be attempted for this issue.