Microsoft fixes critical security vulnerability in Azure CLI

Microsoft fixed a critical security vulnerability in Azure CLI that could let attackers steal credentials from GitHub Actions and Azure DevOps logs

November 16, 2023 12:29 pm | Updated 12:29 pm IST

Microsoft fixed a critical security vulnerability that could be used by attackers to recover plaintext passwords and usernames from Azure DevOps and GitHub Actions.

Microsoft fixed a critical security vulnerability that could be used by attackers to recover plaintext passwords and usernames from Azure DevOps and GitHub Actions. | Photo Credit: AP

Microsoft fixed a critical security vulnerability that could be used by attackers to recover plaintext passwords and usernames from log files created by the affected CLI commands and published by Azure DevOps and GitHub Actions.

The vulnerability was identified by a security researcher from Palo Alto’s Prisma Cloud.

Customers who recently used Azure CLI commands were notified through the Azure Portal, Microsoft said. The company has also implemented a new Azure CLI default configuration to bolster security measures, aiming to prevent accidental disclosure of sensitive information.

With the update, settings now restrict the presentation of secrets in the output generated by update commands concerning services within the App Service Family, including Web Apps and Functions.

(For top technology news of the day, subscribe to our tech newsletter Today’s Cache)

“We’re expanding our credential redaction capabilities in GitHub Actions and Azure Pipelines to identify a wider number of recognizable key patterns in build logs and mask them” Microsoft shared in a blog post.

The company has also advised existing users to update Azure CLI to the latest release, avoid exposing Azure CLI output in logs or publicly accessible location and rotate keys on a regular basis.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.