CVE Vulnerabilities

CVE-2024-49056

Authentication Bypass by Assumed-Immutable Data

Published: Nov 12, 2024 | Modified: Jan 07, 2025
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Authentication bypass by assumed-immutable data on airlift.microsoft.com allows an authorized attacker to elevate privileges over a network.

Weakness

The authentication scheme or implementation uses key data elements that are assumed to be immutable, but can be controlled or modified by the attacker.

Affected Software

NameVendorStart VersionEnd Version
Airlift_microsoft_comMicrosoft- (including)- (including)

Potential Mitigations

References