March 30, 2023, 6:53 p.m. | Nadav Noy

Security Boulevard securityboulevard.com




The Legit Security research team has found a vulnerability in Azure Pipelines (CVE-2023-21553) that allows an attacker to execute malicious code in a context of a pipeline workflow, which allows attackers to gain sensitive secrets, move laterally in the organization, and initiate supply chain attacks.


The post Remote Code Execution Vulnerability in Azure Pipelines Can Lead To Software Supply Chain Attack appeared first on Security Boulevard.

attack attackers attacks azure azure pipelines code code execution context cve legit legit security malicious organization pipeline pipelines remote code remote code execution research secrets security security boulevard security research software software supply chain software supply chain attack supply supply chain supply chain attack supply chain attacks team vulnerability

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC