Blog | G5 Cyber Security

Microsoft Azure App Service flaw exposed customer source code

A security flaw found in Microsoft-managed platform for building and hosting web apps led to the exposure of PHP, Node, Python, Ruby, or Java customer source code for at least four years, since 2017. Only Azure App Service Linux customers were impacted by the issue, with IIS-based applications deployed by Windows customers not being affected. Microsoft mitigated the flaw by updating PHP images to disallow serving the.git folder as static content. The vulnerability, which we dubbed as ‘NotLegit,’ has existed since September 2017.”]

Source: https://www.bleepingcomputer.com/news/security/microsoft-azure-app-service-flaw-exposed-customer-source-code/

Exit mobile version