boostsecurityio / boostsecurityio/lotp

[LOTP] Add Azure Pipelines Logging Command

Open
#60 0 comments 0 reactions 0 assignees View on GitHub
idea
Dominant language
HTML
Stars
164
Forks
14
PR merge metrics
No merged PRs in 30d

Description

# Description of the LOTP tool

Logging command in Azure pipelines can be used for RCE if able to be print to log.

# Documentation

https://www.legitsecurity.com/blog/remote-code-execution-vulnerability-in-azure-pipelines-can-lead-to-software-supply-chain-attack

https://learn.microsoft.com/en-us/azure/devops/pipelines/scripts/logging-commands?view=azure-devops&tabs=bash

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no repository file, test, or entry point. Start by reading the Azure Pipelines logging-commands documentation and the linked RCE research, then locate how existing LOTP tools are represented. Done means the Azure Pipelines logging command is added consistently with the project’s existing tools.

Written by the indexing model from the issue text.

Assessment

Tech stack
azure
Domain
devops, security
Issue type
Feature
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.