azure-identity-1.11.4.jar: 1 vulnerabilities (highest severity is: 5.5) - autoclosed #14279
Labels
CVE
Fixes a CVE
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
security
Anything security related
Vulnerable Library - azure-identity-1.11.4.jar
This module contains client library for Microsoft Azure Identity.
Library home page: https://github.com/Azure/azure-sdk-for-java
Path to dependency file: /plugins/repository-azure/build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.azure/azure-identity/1.11.4/59b5ce48888f638b80d85ef5aa0e22a265d3dc89/azure-identity-1.11.4.jar
Found in HEAD commit: 45e73c43e36926a8a03b094ec1ea254f5de91beb
Vulnerabilities
**In some cases, Remediation PR cannot be created automatically for a vulnerability despite the availability of remediation
Details
CVE-2024-35255
Vulnerable Library - azure-identity-1.11.4.jar
This module contains client library for Microsoft Azure Identity.
Library home page: https://github.com/Azure/azure-sdk-for-java
Path to dependency file: /plugins/repository-azure/build.gradle
Path to vulnerable library: /home/wss-scanner/.gradle/caches/modules-2/files-2.1/com.azure/azure-identity/1.11.4/59b5ce48888f638b80d85ef5aa0e22a265d3dc89/azure-identity-1.11.4.jar
Dependency Hierarchy:
Found in HEAD commit: 45e73c43e36926a8a03b094ec1ea254f5de91beb
Found in base branch: main
Vulnerability Details
Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability
Publish Date: 2024-06-11
URL: CVE-2024-35255
CVSS 3 Score Details (5.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: GHSA-m5vv-6r4h-3vj9
Release Date: 2024-06-11
Fix Resolution: 1.12.2
⛑️ Automatic Remediation will be attempted for this issue.
⛑️Automatic Remediation will be attempted for this issue.
The text was updated successfully, but these errors were encountered: