Permissive regular expression in Azure Compute Gallery allows an authorized attacker to elevate privileges locally.
The product uses a regular expression that does not sufficiently restrict the set of allowed values.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Aci_confidential_containers | Microsoft | - (including) | - (including) |
This effectively causes the regexp to accept substrings that match the pattern, which produces a partial comparison to the target. In some cases, this can lead to other weaknesses. Common errors include: