NotLegit: Azure App Service vulnerability exposed hundreds of source code repositories
ID: e7f2333b-a3e2-5526-8929-980f381a552c
STIX ID: report--e7f2333b-a3e2-5526-8929-980f381a552c
Feed Name: Wiz Blog
Threat Score
Wiz disclosed “NotLegit”, a long-standing (since Sept 2017) Azure App Service misconfiguration that left .git directories publicly accessible for PHP, Node, Ruby, and Python apps deployed via Local Git or when files were created before Git deployment, exposing source code and secrets; Microsoft mitigated the issue after disclosure in Oct–Dec 2021 and notified affected customers, but evidence shows active scanning and exploitation in the wild.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
