Impact
Azure Data Factory is vulnerable to server‑side request forgery, allowing an attacker who is not authenticated to direct the service to send HTTP requests to arbitrary URLs. The flaw permits disclosure of internal network data or other sensitive information that the Data Factory instance can reach, effectively leaking data beyond the intended scope of the service. This weakness is associated with CWE‑918 and the authorization bypass (CWE‑862) that allows untrusted input to drive outbound requests without proper checks.
Affected Systems
Microsoft Azure Data Factory services across all regions and subscriptions are affected. Any customer building pipelines, datasets, or integration runtimes in Azure Data Factory can be impacted if the service’s outbound request handling is not constrained by network or policy controls.
Risk and Exploitability
The CVSS score of 8.6 reflects a high‑severity exploitation path. EPSS is not available, so the likelihood of widespread exploitation cannot be quantified, and the vulnerability is not listed in CISA KEV, indicating no confirmed exploits. Based on the description, the likely attack vector is a crafted request to an Azure Data Factory endpoint that resolves to an internal or remote address. The attacker can obtain any data the Data Factory instance can reach, potentially exposing confidential information to an unauthorized party.
OpenCVE Enrichment