Nov. 14, 2023, 8 a.m. |

Microsoft Security Response Center msrc-blog.microsoft.com

Summary Summary The Microsoft Security Response Center (MSRC) was made aware of a vulnerability where Azure Command-Line Interface (CLI) could expose sensitive information, including credentials, through GitHub Actions logs. The researcher, from Palo Alto’s Prisma Cloud, found that Azure CLI commands could be used to show sensitive data and output to Continuous Integration and Continuous Deployment (CI/CD) logs.

actions alto aware azure center cli cloud command credentials data expose found github github actions guidance information interface leaked logs microsoft microsoft security msrc palo palo alto prisma prisma cloud researcher response security sensitive sensitive data sensitive information vulnerability

More from msrc-blog.microsoft.com / Microsoft Security Response Center

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC