AWS, Google, and Azure CLI Tools Could Leak Credentials in Build Logs
ID: 4c2bbfb3-72d7-57f4-8809-4d475d724bdd
STIX ID: report--4c2bbfb3-72d7-57f4-8809-4d475d724bdd
Feed Name: The Hacker News
Threat Score
Orca researchers disclosed “LeakyCLI,” a class of issues where cloud provider CLI commands (AWS, Google Cloud, Azure) can print environment variables to CI/CD logs and inadvertently leak credentials; Microsoft released a patch (CVE-2023-36052) while AWS/Google advise using secrets managers and suppressing output to mitigate exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
