Microsoft paid Tenable a bug bounty for an Azure flaw it says doesn't need a fix, just better documentation
ID: 4f3546f6-804a-547b-9070-c155bf81038e
STIX ID: report--4f3546f6-804a-547b-9070-c155bf81038e
Feed Name: The Register (Security)
Threat Score
Tenable disclosed that Azure Service Tags can be abused to bypass firewall rules and reach other customers' private web resources by controlling server-side HTTP requests from certain Azure services; Microsoft acknowledged the report, paid a bounty, but decided to address it via documentation and guidance rather than a software patch, and reports no observed exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
