Microsoft Azure API Management Service Vulnerabilities Patched

TL;DR
Three new security flaws have been discovered in Microsoft Azure API Management service, including two server-side request forgery (SSRF) flaws and one instance of unrestricted file upload functionality in the API Management developer portal. Exploitation of SSRF flaws can result in loss of confidentiality and integrity, permitting a threat actor to read internal Azure resources and execute unauthorized code. Following responsible disclosure, all the three flaws have been patched by Microsoft.
Topics:technologyapi-management-vulnerability#api-management#api-management-vulnerability#microsoft-azure#path-traversal#security-flaws#ssrf
Want the full story? Read the original reporting
Read on The Hacker News