Medium severity5.3NVD Advisory· Published Oct 16, 2020· Updated Jun 17, 2026
CVE-2020-16904
CVE-2020-16904
Description
An elevation of privilege vulnerability exists in the way Azure Functions validate access keys. An unauthenticated attacker who successfully exploited this vulnerability could invoke an HTTP Function without proper authorization. This security update addresses the vulnerability by correctly validating access keys used to access HTTP Functions.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: N/A
Patches
Vulnerability mechanics
References
1- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-16904nvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.