|
|
|
|
|
by bradford
457 days ago
|
|
Suppose user U has read access to Subscription S, but doesn't have access to keyvault K. If user U can gain access to keyvault K via this exploit, it is scary. [Vendors/Contingent staff will often be granted read-level access to a subscription under the assumption that they won't have access to secrets, for example.] (I'm open to the possibility that I'm misunderstanding the exploit) |
|