CVE-2022-39327
Summary
| CVE | CVE-2022-39327 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-25 17:15:00 UTC |
| Updated | 2023-06-27 17:20:00 UTC |
| Description | Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting machine runs an Azure CLI command where parameter values have been provided by an external source. The vulnerability is only applicable when the Azure CLI command is run on a Windows machine and with any version of PowerShell and when the parameter value contains the `&` or `|` symbols. If any of these prerequisites are not met, this vulnerability is not applicable. Users should upgrade to version 2.40.0 or greater to receive a a mitigation for the vulnerability. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Improper Control of Generation of Code ('Code Injection') in Azure CLI · Advisory · Azure/azure-cli · GitHub |
CONFIRM |
github.com |
|
| [Core] Revert #23514: Rename entry script `az.ps1` to `azps.ps1` by jiasli · Pull Request #24015 · Azure/azure-cli · GitHub |
MISC |
github.com |
|
| [Core] Add `az.ps1` entry script for PowerShell by jiasli · Pull Request #23514 · Azure/azure-cli · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 379058 Microsoft Azure CLI Improper Control of Generation of Code Vulnerability