logo

NotLegit: Azure App Service vulnerability exposed hundreds of source code repositories

ID: e7f2333b-a3e2-5526-8929-980f381a552c

STIX ID: report--e7f2333b-a3e2-5526-8929-980f381a552c

Feed Name: Wiz Blog

Threat Score
75/100

Date Published: 2021-12-21

Date Updated: 2026-05-01

...
...

Wiz disclosed “NotLegit”, a long-standing (since Sept 2017) Azure App Service misconfiguration that left .git directories publicly accessible for PHP, Node, Ruby, and Python apps deployed via Local Git or when files were created before Git deployment, exposing source code and secrets; Microsoft mitigated the issue after disclosure in Oct–Dec 2021 and notified affected customers, but evidence shows active scanning and exploitation in the wild.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.