Azure Data Factory Bugs Expose Cloud Infrastructure
ID: 4f737bcf-cd57-56c9-9450-fc05a51223f1
STIX ID: report--4f737bcf-cd57-56c9-9450-fc05a51223f1
Feed Name: Dark Reading
Date Published: 2024-12-17
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Unit 42 found three issues in Azure Data Factory's Apache Airflow integration — a misconfigured Kubernetes RBAC, improper secret handling for the Geneva service, and weak Geneva authentication — that could let an attacker inject malicious DAG files (via writable storage or compromised Git repos) to obtain reverse shells on Airflow workers, leverage a service account to gain cluster admin (shadow admin) privileges, and subsequently exfiltrate data or deploy malware across the Azure environment; Microsoft was informed and the issues were mitigated.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
