VDB

GCVE-110-CLOUD-2023-0060

GCVE-110-CLOUD-2023-0060
Advisory Published
Vulnetix · Advisory published January 17, 2023
SSRF vulnerabilities were discovered in four Azure services: unauthenticated SSRF in Azure Digital Twins Explorer and Azure Functions, and authenticated SSRF in Azure API Management Service and Azure Machine Learning Service. All four vulnerabilities were full (non-blind) SSRF. The impact of these vulnerabilities was limited: while they would have allowed an adversary to scan local ports and find new services, endpoints, and files; they would not have allowed them to access metadata, connect to internal services, access unauthorized data, or obtain cross-tenant access.

Affected Products

VendorProductVersionsPlatforms
AzureAzure Machine Learning Service, Azure API Management Service, Azure Functions, Azure Digital Twins Explorer
AzureFunctions
AzureMachine Learning
AzureCloud Services

References

advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

73,866 records in the GCVE database · Updated July 19, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›