Property
Languagehcl
Severitylow
CWECWE-320: CWE CATEGORY: Key Management Errors
OWASPA03:2017 - Sensitive Data Exposure
Confidence LevelLow
Impact LevelLow
Likelihood LevelLow

Description#

Automation account variables in Azure are being created without enabling encryption. This means sensitive values stored in these variables are left unprotected and can be accessed in plain text.

Impact#

If these variables contain secrets or confidential information, attackers or unauthorized users could read them, potentially leading to data leaks, privilege escalation, or further compromise of Azure resources.