-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability (CWE-77) indicates command injection in development-time credentials. Both AzureCliCredential and AzurePowerShellCredential execute external shell commands to obtain tokens. The patch in 1.10.2 likely addressed improper input sanitization in these credential types. The high confidence stems from: 1) RCE aligns with command injection in process-executing credentials, 2) The changelog's 'development time credentials' fix reference, and 3) These credentials' inherent risk profile when handling untrusted input in shell commands.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| Azure.Identity | nuget | < 1.10.2 | 1.10.2 |
Ongoing coverage of React2Shell