
CVE-2024-30053 – Azure Migrate Cross-Site Scripting Vulnerability
https://notcve.org/view.php?id=CVE-2024-30053
14 May 2024 — Azure Migrate Cross-Site Scripting Vulnerability Vulnerabilidad de Cross Site Scripting de Azure Migrate • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30053 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2024-26193 – Azure Migrate Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2024-26193
09 Apr 2024 — Azure Migrate Remote Code Execution Vulnerability Vulnerabilidad de ejecución remota de código de Azure Migrate • https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26193 • CWE-285: Improper Authorization •

CVE-2021-42306 – Azure Active Directory Information Disclosure Vulnerability
https://notcve.org/view.php?id=CVE-2021-42306
24 Nov 2021 — An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a user or service in the tenant with application read access to read the private key data that was added to the application. Azure AD addressed this vulnerability by preventing disclosure of any private key values added to the application... • https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-42306 • CWE-522: Insufficiently Protected Credentials •