Azure App Service flaw exposes huge collection of source code repositories


A flaw in Microsoft’s Azure App Service has been exposing customer source code for years, security researchers have discovered.
According to cloud security providers Wiz.io, Microsoft’s platform for building and hosting web apps has contained insecure default behavior in its Linux variant since 2017, and as a result, PHP, Node, Python, Ruby and Java customer source code had been exposed.
The company named the flaw ‘NotLegit’, and said it was “probably exploited in the wild”. IIS-based applications are safe, though. After deploying a vulnerable app of their own, it only took Wiz.io four days to get a threat actor trying to access the contents of the source code folder on the exposed endpoint.
Microsoft fix
However, it can’t be sure if someone knew of the NotLegit flaw, or if it was just a regular scan for exposed .git folders.
“Small groups of customers are still potentially exposed and should take certain user actions to protect their applications, as detailed in several email alerts Microsoft issued between the 7th – 15th of December, 2021,” Wiz.io noted.
Microsoft acknowledged the flaw, and said it already deployed a fix.
“MSRC was informed by Wiz.io, of an issue where customers can unintentionally configure the .git folder to be created in the content root, which would put them at risk for information disclosure. This, when combined with an application configured to serve static content, makes it possible for others to download files not intended to be public,” Microsoft said in an announcement.
To solve the problem, Microsoft updated all PHP images to disallow serving the .git folder as static content as a defense in depth measure, notified impacted customers, as well as those who had the .git folder uploaded to the content directory, and updated its Security Recommendations document with an additional section on securing source code. Finally, it updated the documentation for in-place deployments, as well.
Via BleepingComputer
Audio player loading… A flaw in Microsoft’s Azure App Service has been exposing customer source code for years, security researchers have discovered. According to cloud security providers Wiz.io, Microsoft’s platform for building and hosting web apps has contained insecure default behavior in its Linux variant since 2017, and as a…
Recent Posts
- One of the best AI video generators is now on the iPhone – here’s what you need to know about Pika’s new app
- Apple’s C1 chip could be a big deal for iPhones – here’s why
- Rabbit shows off the AI agent it should have launched with
- Instagram wants you to do more with DMs than just slide into someone else’s
- Nvidia is launching ‘priority access’ to help fans buy RTX 5080 and 5090 FE GPUs
Archives
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- September 2018
- October 2017
- December 2011
- August 2010