QID 379032
Date Published: 2023-11-23
QID 379032: Microsoft Azure CLI REST Command Information Disclosure Vulnerability (CVE-2023-36052)
The Azure Command-Line Interface (CLI) is a cross-platform command-line tool to connect to Azure and execute administrative commands on Azure resources. It allows the execution of commands through a terminal using interactive command-line prompts or a script.
An unauthenticated attacker can search and discover credentials contained in log files which have been stored in open-source repositories.
Affected Versions:
Azure CLI versions prior to v2.53.1
QID Detection Logic:(Authenticated)
The QID checks for Windows registry uninstall path to find out the vulnerable versions of Azure CLI installed.
An attacker could successfully exploit this vulnerability to recover plaintext passwords and usernames from log files created by the affected CLI commands and published by Azure DevOps or GitHub Actions.
For auto upgrade of azure cli version please refer to azure cli auto update.
- CVE-2023-36052 -
msrc.microsoft.com/update-guide/vulnerability/CVE-2023-36052
CVEs related to QID 379032
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| CVE-2023-36052 |
|