<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:19:08 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-07463</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-07463</link>
      <description>bdu:2022-07463</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-07463</guid>
    </item>
    <item>
      <title>certfr-2022-avi-1014 — De multiples vulnérabilités ont été corrigées dans &lt;span
class="textit"&gt;Microsoft Azure&lt;/span&gt;. Elles permettent à un a…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2022-avi-1014</link>
      <description>certfr-2022-avi-1014</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2022-avi-1014</guid>
    </item>
    <item>
      <title>EUVD-2026-232586</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-232586</link>
      <description>EUVD-2026-232586</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-232586</guid>
    </item>
    <item>
      <title>fkie_cve-2022-39327</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2022-39327</link>
      <description>&lt;p&gt;Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting machine runs an Azure CLI command where parameter values have been provided by an external source. The vulnerability is only applicable when the Azure CLI command is run on a Windows machine and with any version of PowerShell and when the parameter value contains the `&amp;amp;` or `|` symbols. If any of these prerequisites are not met, this vulnerability is not applicable. Users should upgrade to version 2.40.0 or greater to receive a a mitigation for the vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting machine runs an Azure CLI command where parameter values have been provided by an external source. The vulnerability is only applicable when the Azure CLI command is run on a Windows machine and with any version of PowerShell and when the parameter value contains the `&amp;amp;` or `|` symbols. If any of these prerequisites are not met, this vulnerability is not applicable. Users should upgrade to version 2.40.0 or greater to receive a a mitigation for the vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2022-39327</guid>
    </item>
    <item>
      <title>GHSA-47xc-9rr2-q7p4 — Improper Control of Generation of Code ('Code Injection') in Azure CLI</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-47xc-9rr2-q7p4</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: azure-cli&lt;/p&gt;
&lt;p&gt;# Description&lt;/p&gt;
&lt;p&gt;In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting machine runs an Azure CLI command where parameter values have been provided by an external source.&lt;/p&gt;
&lt;p&gt;For example: Application X is a web application with a feature that allows users to create Secrets in an Azure KeyVault. Instead of constructing API calls based on user input, Application X uses Azure CLI commands to create the secrets. Application X has input fields presented to the user and the Azure CLI command parameter values are filled based on the user input fields. This input, when formed correctly, could potentially be run as system commands. Below is an example of the resulting Azure CLI command run on the web app&amp;#39;s hosting machine.&lt;/p&gt;
&lt;p&gt;```bash
az keyvault secret set --vault-name SomeVault --name foobar --value &amp;#34;abc123|whoami&amp;#34;
```&lt;/p&gt;
&lt;p&gt;The above command could potentially run the `whoami` command on the hosting machine.&lt;/p&gt;
&lt;p&gt;Interactive, in-terminal use and automation/pipeline scenarios have not been identified as critical risk scenarios.&lt;/p&gt;
&lt;p&gt;## Code injection prerequisites&lt;/p&gt;
&lt;p&gt;The vulnerability is only applicable when the Azure CLI command is run on a Windows machine **_and_** with any version of PowerShell **_and_**when the parameter value contains the `&amp;amp;` or `|` symbols. If any of these prerequisites are not met, this vulnerability is not applicable.&lt;/p&gt;
&lt;p&gt;### 1. The command has to be run on Windows&lt;/p&gt;
&lt;p&gt;The Azure CLI has an entry script th…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: azure-cli&lt;/p&gt;
&lt;p&gt;# Description&lt;/p&gt;
&lt;p&gt;In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting machine runs an Azure CLI command where parameter values have been provided by an external source.&lt;/p&gt;
&lt;p&gt;For example: Application X is a web application with a feature that allows users to create Secrets in an Azure KeyVault. Instead of constructing API calls based on user input, Application X uses Azure CLI commands to create the secrets. Application X has input fields presented to the user and the Azure CLI command parameter values are filled based on the user input fields. This input, when formed correctly, could potentially be run as system commands. Below is an example of the resulting Azure CLI command run on the web app&amp;#39;s hosting machine.&lt;/p&gt;
&lt;p&gt;```bash
az keyvault secret set --vault-name SomeVault --name foobar --value &amp;#34;abc123|whoami&amp;#34;
```&lt;/p&gt;
&lt;p&gt;The above command could potentially run the `whoami` command on the hosting machine.&lt;/p&gt;
&lt;p&gt;Interactive, in-terminal use and automation/pipeline scenarios have not been identified as critical risk scenarios.&lt;/p&gt;
&lt;p&gt;## Code injection prerequisites&lt;/p&gt;
&lt;p&gt;The vulnerability is only applicable when the Azure CLI command is run on a Windows machine **_and_** with any version of PowerShell **_and_**when the parameter value contains the `&amp;amp;` or `|` symbols. If any of these prerequisites are not met, this vulnerability is not applicable.&lt;/p&gt;
&lt;p&gt;### 1. The command has to be run on Windows&lt;/p&gt;
&lt;p&gt;The Azure CLI has an entry script th…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-47xc-9rr2-q7p4</guid>
    </item>
    <item>
      <title>gsd-2022-39327</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2022-39327</link>
      <description>gsd-2022-39327</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2022-39327</guid>
    </item>
    <item>
      <title>PYSEC-2022-43177</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2022-43177</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: azure-cli&lt;/p&gt;
&lt;p&gt;Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting machine runs an Azure CLI command where parameter values have been provided by an external source. The vulnerability is only applicable when the Azure CLI command is run on a Windows machine and with any version of PowerShell and when the parameter value contains the `&amp;amp;` or `|` symbols. If any of these prerequisites are not met, this vulnerability is not applicable. Users should upgrade to version 2.40.0 or greater to receive a a mitigation for the vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: azure-cli&lt;/p&gt;
&lt;p&gt;Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting machine runs an Azure CLI command where parameter values have been provided by an external source. The vulnerability is only applicable when the Azure CLI command is run on a Windows machine and with any version of PowerShell and when the parameter value contains the `&amp;amp;` or `|` symbols. If any of these prerequisites are not met, this vulnerability is not applicable. Users should upgrade to version 2.40.0 or greater to receive a a mitigation for the vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2022-43177</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2022-39327</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-39327</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: azure-cli&lt;/p&gt;
&lt;p&gt;Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting machine runs an Azure CLI command where parameter values have been provided by an external source. The vulnerability is only applicable when the Azure CLI command is run on a Windows machine and with any version of PowerShell and when the parameter value contains the `&amp;amp;` or `|` symbols. If any of these prerequisites are not met, this vulnerability is not applicable. Users should upgrade to version 2.40.0 or greater to receive a a mitigation for the vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:20.04:LTS: azure-cli&lt;/p&gt;
&lt;p&gt;Azure CLI is the command-line interface for Microsoft Azure. In versions previous to 2.40.0, Azure CLI contains a vulnerability for potential code injection. Critical scenarios are where a hosting machine runs an Azure CLI command where parameter values have been provided by an external source. The vulnerability is only applicable when the Azure CLI command is run on a Windows machine and with any version of PowerShell and when the parameter value contains the `&amp;amp;` or `|` symbols. If any of these prerequisites are not met, this vulnerability is not applicable. Users should upgrade to version 2.40.0 or greater to receive a a mitigation for the vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-39327</guid>
    </item>
  </channel>
</rss>
