Microsoft’s Azure App Service has a four-year-old vulnerability that could reveal the source code of web apps written in PHP, Python, Ruby or Node that were deployed using Local Git. The vulnerability could expose passwords and access tokens, along with blueprints for internal infrastructure and finding software vulnerabilities. The bug has almost certainly been exploited in the wild as a zero-day, according to an analysis from Wiz. The firm dubbed the vulnerability NotLegit, and said it has existed since September 2017.”]
Source: https://threatpost.com/microsoft-azure-zero-day-source-code/177270/