Tag

Azure Cli

All articles tagged with #azure cli

Microsoft's November 2023 Patch Tuesday addresses critical bugs and leaked credentials

Originally Published 2 years ago — by BleepingComputer

Featured image for Microsoft's November 2023 Patch Tuesday addresses critical bugs and leaked credentials
Source: BleepingComputer

Microsoft has patched a critical security vulnerability in Azure CLI that could have allowed attackers to steal credentials from GitHub Actions or Azure DevOps logs. The vulnerability, reported by a security researcher, could enable unauthenticated attackers to remotely access plain text contents written by Azure CLI to CI/CD logs. Microsoft advises customers to update to the latest Azure CLI version (2.54) and take steps to prevent accidental exposure of secrets in logs. The company has also implemented new security measures to restrict the presentation of secrets in output and broaden credential redaction capabilities.