Azure / Azure/azure-cli

Disclose fixed security vulnerabilities

Open
#27,971 3 comments 1 reaction 3 assignees Assigned to @jiasli View on GitHub
Azure CLI Team customer-reported feature-request
Dominant language
Python
Stars
4.6k
Forks
3.5k
Avg merge
3d 2h
Merged PRs (30d)
60

Description

**Is your feature request related to a problem? Please describe.**

At the end of October 2023, Azure customers received emails stating

> A recent Azure CLI update has been released that contains important security improvements. It is recommended that you update to the latest version. Ensure you receive the latest security improvements by enabling automatic updates for Azure CLI. For more information, visit the Azure CLI release notes.

The email did not state what kind of security issues were found, but instead referred to Azure CLI notes https://learn.microsoft.com/en-us/cli/azure/release-notes-azure-cli#october-24-2023, which don't contain such information either.

This practice does not allow customers to assess the security impact of staying on an older version of Azure CLI, in cases when an immediate update is not feasible due to operational costs.

The issue was raised as Azure ticket 2310260050000544, but not resolved.

**Describe the solution you'd like**

Security vulnerability disclosure with severity score.

**Describe alternatives you've considered**

None

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.