- RSS feed is now ordered by publication date
- New template for simple contribution of information about a vulnerability or security issue: https://t.co/W6kfOdxHcj
2/2
We've made some updates!
- New website logo
- 137 total vulnerabilities and security issues added by 24 contributors (65 added since website launch)
- New tag system allows searching for issues with specific severities in each CSP: https://t.co/dplxp5JxpG
🧵1/2
@mdecrevoisier This does not seem to be a security mistake by Azure which would fit our criteria of being a cloudvuln (note MSRC did not fix anything), but rather is a privilege escalation within a specific customer environment.
Good to see Azure investing in this. @41thexplorer and I spoke about using @cloudvulndb for cross-industry variant analysis of cloud vulnerabilities in our talk at @fwdcloudsec 22' (https://t.co/xkqR2hjCpK)
We've downgraded this issue to high severity. We're actively working on better defining how we rate these issues. The pre-req that the attacker must know the volume ID was decided to be a significant barrier, along with the volume needing to be shared or unattached.