VDB

GCVE-110-CLOUD-2025-0016

GCVE-110-CLOUD-2025-0016
Advisory Published
Vulnetix · Advisory published March 10, 2025
Azure API Connections were found to allow any reader on a subscription to access backend resources through a proxy endpoint, potentially exposing secrets from Key Vaults, databases, and third-party services. This vulnerability affects various Azure services and external APIs, enabling privilege escalation and unauthorized access to sensitive information.

Affected Products

VendorProductVersionsPlatforms
AzureLogic Apps, Key Vault, SQL Database, Jira, Salesforce, Storage Blobs, Defender ATP
AzureCloud Services

References

advisory

Browse GCVE Records

74,198 records in the GCVE database · Updated July 21, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›