Azure App Service
by Microsoft
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-1372 | Cri | 0.66 | 10.0 | 0.19 | Oct 10, 2019 | An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to… | ||
| CVE-2026-58630 | Cri | 0.65 | 10.0 | 0.01 | Jul 24, 2026 | Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. | ||
| CVE-2023-21777 | Hig | 0.57 | 8.7 | 0.00 | Feb 14, 2023 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | ||
| CVE-2018-8600 | Med | 0.40 | 6.1 | 0.02 | Nov 14, 2018 | A Cross-site Scripting (XSS) vulnerability exists when Azure App Services on Azure Stack does not properly sanitize user provided input, aka "Azure App Service Cross-site Scripting Vulnerability." This affects Azure App. |
- risk 0.66cvss 10.0epss 0.19
An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to…
- risk 0.65cvss 10.0epss 0.01
Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.7epss 0.00
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
- risk 0.40cvss 6.1epss 0.02
A Cross-site Scripting (XSS) vulnerability exists when Azure App Services on Azure Stack does not properly sanitize user provided input, aka "Azure App Service Cross-site Scripting Vulnerability." This affects Azure App.