boostsecurityio / boostsecurityio/lotp
[LOTP] Add Azure Pipelines Logging Command
- Dominant language
- HTML
- Stars
- 164
- Forks
- 14
- PR merge metrics
- No merged PRs in 30d
Description
# Description of the LOTP tool
Logging command in Azure pipelines can be used for RCE if able to be print to log.
# Documentation
https://www.legitsecurity.com/blog/remote-code-execution-vulnerability-in-azure-pipelines-can-lead-to-software-supply-chain-attack
https://learn.microsoft.com/en-us/azure/devops/pipelines/scripts/logging-commands?view=azure-devops&tabs=bash
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue names no repository file, test, or entry point. Start by reading the Azure Pipelines logging-commands documentation and the linked RCE research, then locate how existing LOTP tools are represented. Done means the Azure Pipelines logging command is added consistently with the project’s existing tools.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure
- Domain
- devops, security
- Issue type
- Feature
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 30/100