Impact
The vulnerability is an authentication flaw that enables a user who has already authorized access to gain higher privileges within Azure Spring Apps. The weakness corresponds to CWE-287, which focuses on authentication failures. Resulting in unauthorized users potentially performing actions reserved for privileged accounts, thereby compromising system confidentiality, integrity, or availability. This has been scored a high severity of 8.2 on the CVSS system.
Affected Systems
Microsoft Azure Spring Apps is the only vendor/product identified as impacted. The description does not specify version details, so all deployments of Azure Spring Apps are potentially susceptible until an official fix is provided.
Risk and Exploitability
The CVSS score of 8.2 indicates substantial risk, yet the EPSS score is below 1%, suggesting that, as of now, the likelihood of exploitation is low. The vulnerability is not listed in the CISA KEV catalog. An attacker is inferred to use the network as the attack vector, abusing legitimate access to elevate privileges. Exploitation would require the ability to authenticate to the service, after which privilege levels can be increased without further authentication.
OpenCVE Enrichment