Orca security researchers disclosed that AWS and Google Cloud CLIs are exposed to the exact same Microsoft Azure CLI vulnerability that risked exposing credentials in logs. Dubbed LeakyCLI, some commands on AWS CLI and Gcloud CLI can expose sensitive information, in the form of environment variables, which can be collected by adversaries when published by tools such as GitHub Actions. There is no CVE ID assigned to the AWS and Gcloud versions of this vulnerability. 🔗 https://orca.security/resources/blog/leakycli-aws-google-cloud-command-line-tools-can-expose-sensitive-credentials-build-logs/

#vulnerability #AWS #GoogleCloud #LeakyCI #CVE_2023_36052

LeakyCLI: AWS and Google Cloud Command-Line Tools Can Expose Sensitive Credentials in Build Logs

Azure, AWS, and Gcloud CLI commands may expose sensitive info on GitHub Actions. This vulnerability can expose credentials and have far reaching consequences.

Orca Security