logo

Microsoft paid Tenable a bug bounty for an Azure flaw it says doesn't need a fix, just better documentation

ID: 4f3546f6-804a-547b-9070-c155bf81038e

STIX ID: report--4f3546f6-804a-547b-9070-c155bf81038e

Feed Name: The Register (Security)

Threat Score
60/100

Date Published: 2024-06-05

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Tenable disclosed that Azure Service Tags can be abused to bypass firewall rules and reach other customers' private web resources by controlling server-side HTTP requests from certain Azure services; Microsoft acknowledged the report, paid a bounty, but decided to address it via documentation and guidance rather than a software patch, and reports no observed exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.