Dirty DAG: New Vulnerabilities in Azure Data Factory’s Apache Airflow Integration
ID: 6df58b2b-301d-5ae1-a818-c6fedd40db22
STIX ID: report--6df58b2b-301d-5ae1-a818-c6fedd40db22
Feed Name: Palo Alto Networks Unit 42
Unit 42 discovered and demonstrated a chained set of vulnerabilities in Azure Data Factory's managed Apache Airflow offering: writable DAG sources or compromised credentials allow attackers to inject malicious DAGs that yield a reverse shell, escalate via a cluster-admin service account token, break out to host VMs, enumerate Azure managed identities and resources through IMDS/WireServer, and abuse poorly secured internal Geneva service APIs to access or manipulate storage, event hubs and logs—enabling shadow administrator control, data exfiltration and covert operations; mitigations and coordination with Microsoft are described.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
