wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
308 stars 62 forks source link

[Contribution] Confused Deputy Vulnerability in Microsoft Defender for Cloud #329

Open korniko98 opened 3 months ago

korniko98 commented 3 months ago

Summary (give a brief description of the issue)

Microsoft Defender for Cloud, Azure’s built-in CSPM, at one point provided customers with a flawed configuration template through their public GitHub repository. In the rare cases in which this template was deployed, under certain, limited circumstances, Defender for Cloud’s security findings could be disclosed to unauthorized third parties.

References (provide links to blogposts, etc.)

https://www.linkedin.com/pulse/confused-deputy-vulnerability-microsoft-defender-cloud-brandon-evans-9fyge/