binarysecurity.no/posts/2024/09/apim-privilege-escalation

Preview meta tags from the binarysecurity.no website.

Linked Hostnames

5

Search Engine Appearance

Google

https://binarysecurity.no/posts/2024/09/apim-privilege-escalation

Escalating from Reader to Contributor in Azure API Management

This blog post shows how a user with Reader-level access to an Azure API Management resource actually had the equivalent of Contributor-level access, allowing the user to read, modify and even delete configurations of the resource via the Direct Management API. This was possible because a regular user with read access to the Azure APIM resource was allowed to read the keys of any APIM user via the Azure Resource Manager Rest API. The keys can be used to generate SharedAccessSignatures to authenticate to the Direct Management API, giving access to perform any management operation on the API Management resource.



Bing

Escalating from Reader to Contributor in Azure API Management

https://binarysecurity.no/posts/2024/09/apim-privilege-escalation

This blog post shows how a user with Reader-level access to an Azure API Management resource actually had the equivalent of Contributor-level access, allowing the user to read, modify and even delete configurations of the resource via the Direct Management API. This was possible because a regular user with read access to the Azure APIM resource was allowed to read the keys of any APIM user via the Azure Resource Manager Rest API. The keys can be used to generate SharedAccessSignatures to authenticate to the Direct Management API, giving access to perform any management operation on the API Management resource.



DuckDuckGo

https://binarysecurity.no/posts/2024/09/apim-privilege-escalation

Escalating from Reader to Contributor in Azure API Management

This blog post shows how a user with Reader-level access to an Azure API Management resource actually had the equivalent of Contributor-level access, allowing the user to read, modify and even delete configurations of the resource via the Direct Management API. This was possible because a regular user with read access to the Azure APIM resource was allowed to read the keys of any APIM user via the Azure Resource Manager Rest API. The keys can be used to generate SharedAccessSignatures to authenticate to the Direct Management API, giving access to perform any management operation on the API Management resource.

  • General Meta Tags

    10
    • title
      Escalating from Reader to Contributor in Azure API Management
    • title
      Escalating from Reader to Contributor in Azure API Management | Binary Security AS
    • charset
      utf-8
    • viewport
      width=device-width, initial-scale=1, user-scalable=no
    • theme-color
      #ffffff
  • Open Graph Meta Tags

    6
    • og:title
      Escalating from Reader to Contributor in Azure API Management
    • US country flagog:locale
      en_US
    • og:description
      This blog post shows how a user with Reader-level access to an Azure API Management resource actually had the equivalent of Contributor-level access, allowing the user to read, modify and even delete configurations of the resource via the Direct Management API. This was possible because a regular user with read access to the Azure APIM resource was allowed to read the keys of any APIM user via the Azure Resource Manager Rest API. The keys can be used to generate SharedAccessSignatures to authenticate to the Direct Management API, giving access to perform any management operation on the API Management resource.
    • og:url
      https://www.binarysecurity.no/posts/2024/09/apim-privilege-escalation
    • og:site_name
      Binary Security AS
  • Twitter Meta Tags

    3
    • twitter:card
      summary
    • twitter:site
      @binarysecnorway
    • twitter:creator
      @Christian Håland
  • Link Tags

    6
    • alternate
      https://www.binarysecurity.no/feed.xml
    • apple-touch-icon
      /assets/images/apple-touch-icon.png
    • canonical
      https://www.binarysecurity.no/posts/2024/09/apim-privilege-escalation
    • icon
      /assets/images/favicon-32x32.png
    • icon
      /assets/images/favicon-16x16.png

Emails

1

Links

21