Azure App Service On Azure Stack
by Microsoft
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-1372 | Cri | 0.66 | 10.0 | 0.19 | Oct 10, 2019 | An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to… | ||
| CVE-2023-21777 | Hig | 0.57 | 8.7 | 0.00 | Feb 14, 2023 | Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability | ||
| CVE-2018-8600 | Med | 0.40 | 6.1 | 0.02 | Nov 14, 2018 | A Cross-site Scripting (XSS) vulnerability exists when Azure App Services on Azure Stack does not properly sanitize user provided input, aka "Azure App Service Cross-site Scripting Vulnerability." This affects Azure App. | ||
| CVE-2025-53765 | Med | 0.29 | 4.4 | 0.00 | Aug 12, 2025 | Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally. |
- risk 0.66cvss 10.0epss 0.19
An remote code execution vulnerability exists when Azure App Service/ Antares on Azure Stack fails to check the length of a buffer prior to copying memory to it.An attacker who successfully exploited this vulnerability could allow an unprivileged function run by the user to…
- risk 0.57cvss 8.7epss 0.00
Azure App Service on Azure Stack Hub Elevation of Privilege Vulnerability
- risk 0.40cvss 6.1epss 0.02
A Cross-site Scripting (XSS) vulnerability exists when Azure App Services on Azure Stack does not properly sanitize user provided input, aka "Azure App Service Cross-site Scripting Vulnerability." This affects Azure App.
- risk 0.29cvss 4.4epss 0.00
Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.