该漏洞允许:
受影响范围: Azure Front Door 标准版与高级版(2026-01-22 之前的补丁前构建版本)
利用仅需公开端点暴露 + 有效的 Azure 资源 ID 格式。 在默认易受攻击的配置中,无需订阅级凭据。
已测试的攻击向量:
用法:
python poc.py --target https://target-frontend.azurefd.net --afd-id /subscriptions/xxxx/resourceGroups/rg/providers/Microsoft.Cdn/profiles/xxxx
包含实验环境搭建(setup-lab.ps1 + Bicep)。
下载:
联系方式:X(推特)上的 @B1gh0rnn(私信开放)。