azure-automation-variable-value

Unencrypted Automation variables are returned in plaintext and may hold credentials or connection strings.

azurecritical service: azure:automation emits ContainsSecret

Where it sits

locationMicrosoft.Automation/automationAccounts/variables.properties.value
location kindconfig_field
data kindscredential password api_key access_key secret_key oauth_token connection_string
emits edgeContainsSecret
serviceAzure Automation (azure:automation)

Collection recipe

access moderead_api
operationVariable - Get
response pathproperties.value
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.Automation/automationAccounts/variables/read

References

move · open · esc close