CVE-2022-30187 is an information disclosure vulnerability affecting Microsoft Azure Storage Blobs and Queues libraries. With a CVSS score of 4.7 (Medium), it has a local attack vector and high attack complexity, potentially leading to sensitive information exposure. Despite media coverage and community discussion, there is no evidence of active exploitation, nor are public exploit codes available in common repositories like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.13.0CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_storage_blobs:*:*:*:*:*:.net:*:* | ||
< 12.13.0CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_storage_blobs:*:*:*:*:*:python:*:* | ||
< 12.18.0CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_storage_blobs:*:*:*:*:*:java:*:* | ||
< 12.4.0CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_storage_queue:*:*:*:*:*:python:*:* | ||
< 12.11.0CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_storage_queue:*:*:*:*:*:.net:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk Enterprise - July 2025
Jul 7, 2025Microsoft: CBC Padding Oracle in Azure Blob Storage Encryption Library
Jul 13, 2022Azure Storage Library Information Disclosure Vulnerability
Jul 12, 2022