QID 376148
Date Published: 2021-12-16
QID 376148: Azure ms-rest-nodeauth Code Injection Vulnerability
The azure/ms-rest-nodeauth package provides different authentication mechanisms meant to be used with a select set of packages from the Azure SDK for JavaScript and TypeScript.
Affected Versions:
ms-rest-nodeauth 3.0.7 and earlier
QID Detection logic:(authenticated)
It checks for vulnerable version of ms-rest-nodeauth by reading the package.json file
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code on the target system.
Solution
Please refer to advisory: MSRC Advisory for affected packages and patching details.
Vendor References
- CVE-2021-28458 -
msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2021-28458
CVEs related to QID 376148
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2021-28458 |
|
||
| Release Notes |
|