Azure AD credentials exposed publicly

infosecurity-magazine.com

Azure AD credentials, including ClientId and ClientSecret, were exposed in a publicly accessible appsettings.json file, creating a significant security risk. This vulnerability allows attackers to authenticate directly to Microsoft's OAuth 2.0 endpoints, potentially impersonating the application and accessing sensitive Microsoft 365 resources. The exposure is attributed to common cloud misconfigurations, highlighting the need for proper secrets management and secure deployment practices.


With a significance score of 2.9, this news ranks in the top 9.6% of today's 28158 analyzed articles.

Get summaries of news with significance over 5.5 (usually ~10 stories per week). Read by 10,000+ subscribers:


Azure AD credentials exposed publicly | News Minimalist