VDB

GCVE-110-CLOUD-2023-0007

GCVE-110-CLOUD-2023-0007
Advisory Published
Vulnetix · Advisory published December 12, 2023
A way to manage Azure OpenAI deployments via the Data Plane was discovered, bypassing key security controls. This allows creation/modification/deletion of deployments without the usual protections of Resource Manager Locks, Azure Policy, and Entra ID authentication.

Affected Products

VendorProductVersionsPlatforms
Azureentra_id
AzureOpenAI
AzureEntra
AzureCloud Services

References

advisory
advisory

Browse GCVE Records

73,873 records in the GCVE database · Updated July 20, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›