Web Hack List

Collected research

Finding SSRFs in Azure DevOps

Maps several Azure DevOps server-side URL-fetching features and shows how weak validation can be turned into SSRF against internal services. The research develops practical bypasses and demonstrates impact across hosted build and integration workflows.

Record

Researcher
Torjus Bryne Retterstøl and @Torjus Bryne Retterstøl
Published by
Binary Security AS
Date

In the archive

Tags

This page is the archive's own catalogue record. The research is the work of Torjus Bryne Retterstøl and @Torjus Bryne Retterstøl, first published at the original source. Preserved copies are kept so the citation survives its host.