craftcms/azure-blob is vulnerable to Information Disclosure
91
Critical Risk
Affected versions of this package are vulnerable to an information disclosure vulnerability due to insufficient access control on a controller endpoint. Under certain conditions, unauthenticated or improperly authorized requests could retrieve Azure Blob container metadata or related sensitive information that should be restricted, potentially leaking internal configuration details. The issue is fixed by adding proper permission checks (such as requiring admin privileges and appropriate request validation) before serving container data, preventing unauthorized access and mitigating the information disclosure risk.
You are affected if you are using a version that falls within the vulnerable range.
craftcms/azure-blob is vulnerable to Information Disclosure in versions 1.0.0 - 2.1.0.
Upgrade the craftcms/azure-blob library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant