question

TinoSchinnerlingprof-3304 avatar image
0 Votes"
TinoSchinnerlingprof-3304 asked TinoSchinnerlingprof-3304 commented

CVE-2022-22963

Hi,

last days there was a vulnerability issue CVE-2022-22963 according to spring cloud found. I wonder if there is an official statement from Microsoft if their services (e.g. Azure, Azure DevOps) are affected by this leak.
I assume that Azure DevOps does not contain any Java Spring Cloud components and is therefore not affected. Is there an official statement from Microsoft on the subject?

Thanks in advance

azure-spring-cloud
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

MikeUrnun avatar image
0 Votes"
MikeUrnun answered TinoSchinnerlingprof-3304 commented
· 2
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thanks Mike,

thats what i've already seen, but there is no comment about the issue CVE-2022-22963 yet. So it would be grateful if somebody has detailed information about it or has tested azure services, because we need an answer for the security department of the company.

Thanks.

0 Votes 0 ·
MikeUrnun avatar image MikeUrnun TinoSchinnerlingprof-3304 ·

@TinoSchinnerlingprof-3304 The same blog post was updated to include CVE-2022-22963 in its guidance:

April 11, 2022 update – Azure Web Application Firewall (WAF) customers with Regional WAF with Azure Application Gateway now has enhanced protection for critical Spring vulnerabilities – CVE-2022-22963, CVE-2022-22965, and CVE-2022-22947. See Detect and protect with Azure Web Application Firewall (Azure WAF) section for details.

0 Votes 0 ·