logo

Database

Azure Admin Privileges

Description

Detects Azure Function Apps that have been granted administrative role assignments. Function Apps with admin privileges represent a security risk since they could be exploited to gain extensive control over Azure resources and potentially compromise the entire environment.

Weakness:

319 - Insecure service configuration - Roles

Category: Functionality Abuse

Detection Strategy

    Scans all Azure Function Apps in the subscription

    Checks if any Function App has been assigned one of these administrative roles: Owner, Contributor, Role Based Access Control Administrator, User Access Administrator, or Access Review Operator Service Role

    Reports a vulnerability if a Function App is found with any of these admin role assignments

Severity v4.0

1.3

Low

Method ID

CSPM-9L1ID

Technique

CSPM

Target

AZURE

Technology

WEB_APP

CWE ID(s)

CWE-266