Back to directory
WRITEUP #1347

Remote Code Execution Vulnerability in Azure Pipelines Can Lead To Software Supply Chain Attack

RCECI/CDSupply chain attack
byNadav Noy
Program
Microsoft (Azure DevOps Pipelines)
Published
Mar 30, 2023
Added to HackDex
Mar 31, 2023
Read Full Writeuphttps://www.legitsecurity.com/blog/remote-code-execution-vulnerability-in-azure-pipelines-can-lead-to-software-supply-chain-attack
RELATED WRITEUPS
Revival Hijack – PyPI hijack technique exploited in the wild, puts 22K packages at risk
AI / LLMCI/CD
Vulnerabilities in Open Source C2 Frameworks
RCEOS command injection
[2,500$ Bug Bounty Write-Up] Remote Code Execution (RCE) via unclaimed Node package
RCEDependency confusion
Attacking PowerShell CLIXML Deserialization
DeserializationInsecure deserialization
Zero-Click Calendar invite — Critical zero-click vulnerability chain in macOS
RCEArbitrary file write

Built with ❤️ by Shubham Rawat