logo

Azure Data Factory Bugs Expose Cloud Infrastructure

ID: 4f737bcf-cd57-56c9-9450-fc05a51223f1

STIX ID: report--4f737bcf-cd57-56c9-9450-fc05a51223f1

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-12-17

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Unit 42 found three issues in Azure Data Factory's Apache Airflow integration — a misconfigured Kubernetes RBAC, improper secret handling for the Geneva service, and weak Geneva authentication — that could let an attacker inject malicious DAG files (via writable storage or compromised Git repos) to obtain reverse shells on Airflow workers, leverage a service account to gain cluster admin (shadow admin) privileges, and subsequently exfiltrate data or deploy malware across the Azure environment; Microsoft was informed and the issues were mitigated.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.