Malconfigured Kubernetes Role-Based Access Control in Azure Airflow Might Make Whole Cluster Vulnerable to Attacks
A team of cybersecurity analysts has detected three security vulnerabilities in Microsoft’s integration of Azure Data Factory with Apache Airflow, which, if effectively abused, may have granted a malicious actor the opportunity to perform a range of clandestine operations, such as extracting data and deploying malware.
“By capitalizing on these vulnerabilities, threat actors could establish enduring access as clandestine administrators.
“By capitalizing on these vulnerabilities, threat actors could establish enduring access as clandestine administrators.
