MEDIUMVulnerability
Global
Default Azure Automation Setting Enables Cross-Tenant Identity Takeover
·Source: Dark Reading
Updated:
Executive Summary
Microsoft addressed a public-by-default configuration and chain of code flaws in Azure Automation which could have let attackers seize another tenant's identity and access other tenants' data, credentials, and cloud workloads.
Analysis
Microsoft addressed a public-by-default configuration and chain of code flaws in Azure Automation which could have let attackers seize another tenant's identity and access other tenants' data, credentials, and cloud workloads.