HomeSecurityGitHub: Fixed a serious vulnerability discovered by Google

GitHub: Fixed a serious vulnerability discovered by Google

GitHub has finally patched a serious vulnerability reported to it by security Google's. The researchers had updated GitHub three months ago.

GitHub vulnerability

The vulnerability affected GitHub's Actions feature . According to Google researcher Felix Wilhelm, the vulnerability made the Actions tool vulnerable to "injection attacks" .

Google had said that this was a very serious vulnerability, however GitHub did not immediately respond as it claimed that it was a “moderate security vulnerability”.

The Google Project Zero team usually publicly discloses bugs they find 90 days after they are reported to the appropriate authority. The 90-day period passed, and GitHub still hadn't fixed the vulnerability. researchers gave them another 14 days, but still nothing happened. So they decided to disclose the vulnerability (in early November).

A day before the planned disclosure (after an extension had been granted), GitHub told Google that it would not disable the vulnerable Actions workflow commands until November 2nd and asked for an additional 48 hours. However, these extra hours would be to inform customers about a future resolution to the issue, not to fix the vulnerability.

Google

Google's research team decided to disclose the vulnerability and not give more time, since 104 days had already passed since the initial report on GitHub.

GitHub finally patched the vulnerability last week, disabling the old Actions runner commands, “set-env” and “add-path”, as researcher Wilhelm had suggested.

The fix was released on November 16 , two weeks after Google disclosed the vulnerability

As Wilhelm said, Action was vulnerable to injection attacks, due to the vulnerability that could ultimately lead to malicious code execution.

Now that GitHub has disabled the two vulnerable commands, Wilhelm has updated his report and confirmed that the issue has been resolved.

Source: ZDNet

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS