Skip to content

[Aikido] Fix security issue in Azure.Core via minor version upgrade from 1.38.0 to 1.59.0 in Aikido.Zen.DotNetFramework#352

Open
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/AIK-15912-update-packages-55086596-vq5k
Open

[Aikido] Fix security issue in Azure.Core via minor version upgrade from 1.38.0 to 1.59.0 in Aikido.Zen.DotNetFramework#352
aikido-autofix[bot] wants to merge 1 commit into
mainfrom
fix/AIK-15912-update-packages-55086596-vq5k

Conversation

@aikido-autofix

Copy link
Copy Markdown
Contributor

Upgrade Azure.Core to fix credential leakage vulnerability where bearer tokens are exposed to unintended redirect hosts.

✅ 1 CVE resolved by this upgrade

This PR will resolve the following CVEs:

Issue Severity           Description
AIKIDO-2026-895105
MEDIUM
[Azure.Core] Bearer token authentication policy fails to strip credentials during cross-host redirects, allowing access tokens to be sent to unintended hosts. This enables credential theft and unauthorized access to resources by attackers controlling redirect targets.
🔗 Related Tasks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants