Intel

AIKIDO-2024-10055

@pulumi/azure is vulnerable to Insufficiently Protected Credentials

Insufficiently Protected Credentials Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 25, 2024

40

Medium Risk

This Affects:

JS@pulumi/azure
0.12.0 - 5.64.0
Fixed in 5.64.1
Are you affected? Scan for Free

TL;DR

Affected versions of the package expose authentication-related configuration settings in plaintext within the state file.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

@pulumi/azure is vulnerable to Insufficiently Protected Credentials in versions 0.12.0 - 5.64.0.

How to fix this

Upgrade the @pulumi/azure library to the patch version.