Information Exposure Affecting azure-storage-queue package, versions [,12.4.0)
Attack Complexity
High
Confidentiality
High
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications-
snyk-id
SNYK-PYTHON-AZURESTORAGEQUEUE-2949174
-
published
13 Jul 2022
-
disclosed
13 Jul 2022
-
credit
Sophie Schmieg
Introduced: 13 Jul 2022
CVE-2022-30187 Open this link in a new tabHow to fix?
Upgrade azure-storage-queue
to version 12.4.0 or higher.
Overview
azure-storage-queue is a Microsoft Azure Azure Queue Storage Client Library for Python
Affected versions of this package are vulnerable to Information Exposure. Attackers can expose the contents of a file or blob when client-side encryption is in use.
NOTE: The vendor advises that client-side encryption is a very uncommon use case.