Sunday, Oct 4, 2026
English News
  • Hyderabad
  • Telangana
  • AP News
  • India
  • World
  • Entertainment
  • Sport
  • Science and Tech
  • Business
  • Rewind
  • ...
    • NRI
    • View Point
    • cartoon
    • My Space
    • Education Today
    • Reviews
    • Property
    • Lifestyle
E-Paper
  • NRI
  • View Point
  • cartoon
  • My Space
  • Reviews
  • Education Today
  • Property
  • Lifestyle
Home | News | Microsoft Informs Customers About Security Bug In Azure Cloud

Microsoft informs customers about security bug in Azure Cloud

"This, when combined with an application configured to serve static content, makes it possible for others to download files not intended to be public," Microsoft said in a statement late on Thursday.

By IANS
Updated On - 24 December 2021, 12:59 PM
Microsoft informs customers about security bug in Azure Cloud
whatsapp facebook twitter telegram

New Delhi: Microsoft has informed users about a ‘NotLegit’ bug in Azure Cloud that may have put some customers’ data at hacking risk.

The Microsoft’s Security Response Centre (MSRC) was informed by Wiz.io, a cloud security vendor, of an issue where customers can unintentionally configure the ‘.git folder’ to be created in the content root, which would put them at risk for information disclosure.


“This, when combined with an application configured to serve static content, makes it possible for others to download files not intended to be public,” Microsoft said in a statement late on Thursday.

“We have notified the limited subset of customers that we believe are at risk due to this and we will continue to work with our customers on securing their applications,” the company added.

App Service Linux customers who deployed applications using Local Git after files were created or modified in the content root directory are impacted.

“This happens because the system attempts to preserve the currently deployed files as part of repository contents, and activates what is referred to as in-place deployments by deployment engine (Kudu),” Microsoft informed.

Not all users of ‘Local Git’ were impacted by the vulnerability and the Azure App Service Windows was not affected, the company said.

Microsoft updated all PHP images to disallow serving the .git folder as static content as a defence in depth measure.

“We have notified customers who were impacted due to the activation of in-place deployment with specific guidance on how to mitigate the issue,” the company informed.

The Wiz Research Team said it first notified Microsoft of the issue on October 7 and the fix was deployed in November and customers were notified by December.

Wiz was paid a bug bounty of $7,500, reports ZDNet.

“Small groups of customers are still potentially exposed and should take certain user actions to protect their applications, as detailed in several email alerts Microsoft issued between the 7th – 15th of December, 2021,” said Wiz.

  • Follow Us :
  • Tags
  • Azure Cloud
  • Microsoft

Related News

  • Telangana targets 5 GW hyperscale data centre capacity by 2029: Sridhar Babu

    Telangana targets 5 GW hyperscale data centre capacity by 2029: Sridhar Babu

  • AI must stay under human control: Satya Nadella

    AI must stay under human control: Satya Nadella

  • Microsoft opens Hyderabad cloud region to boost India’s AI, cloud infra

    Microsoft opens Hyderabad cloud region to boost India’s AI, cloud infra

  • India emerges as major global hub for AI data centre investments

    India emerges as major global hub for AI data centre investments

Latest News

  • North Korea’s Kim oversees hypersonic missile launch, calls for bolstering war deterrent

    26 minutes ago
  • KTR invited as guest of honour at US healthcare summit

    30 minutes ago
  • Rajasthan: Union Minister Bhupender Yadav releases two rare Great Indian Bustards in Jaisalmer

    51 minutes ago
  • Market outlook: RBI policy stance, Q2 earnings, West Asia tensions key triggers next week

    52 minutes ago
  • Saudi airstrikes reported on Yemen’s Houthi-held capital Sanaa

    57 minutes ago
  • flydubai crew asked passengers to free co-pilot after he was overpowered: Report

    1 hour ago
  • Explainer: How CO₂ rise is changing savanna grasslands

    2 hours ago
  • Honest Money: The patient dragon—what twenty years of quiet preparation looks like, and what it means for India

    2 hours ago

company

  • Home
  • About Us
  • Contact Us
  • Privacy Policy

business

  • Subscribe

telangana today

  • Telangana
  • Hyderabad
  • Latest News
  • Entertainment
  • World
  • Andhra Pradesh
  • Science & Tech
  • Sport

follow us

  • Telangana Today Telangana Today
Telangana Today Telangana Today

© Copyrights 2024 TELANGANA PUBLICATIONS PVT. LTD. All rights reserved. Powered by Veegam

Telangana Today App