HomeSecurityGitHub: Key rotation due to vulnerability that exposed credentials

GitHub: Key rotation due to vulnerability that exposed credentials

GitHub has implemented a key rotation due to a vulnerability that was patched in December. The vulnerability could have allowed malicious users to access credentials inside production containers via environment variables.

GitHub key rotation credentials

The vulnerability, tracked as CVE-2024-0200, could allow attackers to perform remote code execution on unpatched servers.

Updates were also released yesterday (3.8.13, 3.9.8, 3.10.5 and 3.11.3) to GitHub Enterprise Server (GHES).

See also: GitHub: Its abuse by cybercriminals is becoming more frequent

While the vulnerability allows access to environment variables of a production container (including credentials), successful exploitation requires authentication with an organization owner role (with admin access to the organization).

“On December 26, 2023, GitHub received a report through the Bug Bounty Program indicating a vulnerability that, if exploited, could allow access to credentials within a production container. We patched this vulnerability on GitHub.com the same day and began rotating all potentially exposed credentials,” said GitHub VP and Deputy Chief Security Officer Jacob DePriest.

The company also says that after investigation, it was determined that this vulnerability had not been used in attacks. However, Github decided to perform key rotation, in accordance with the security , and as a precaution.

See also: GitHub: Enable 2FA before the upcoming deadline

While most of the keys replaced by GitHub in December do not require any action from the customer, those using the commit signing key and GitHub Actions, GitHub Codespaces, and Dependabot customer encryption keys will need to import the new public keys.

GitHub: Key rotation due to vulnerability that exposed credentials

Meaning of key rotation

Key rotation is a security process that involves regularly changing the cryptographic keys used to protect data. This can help prevent breaches security, as an attacker would need to reacquire the key each time it changes.

In the case of GitHub, key rotation can help reduce the impact of a credential-exposing bug. If a compromised key is used to access sensitive information, changing the key will force the attacker to start the attack over again.

See also: GitHub passkeys: Available for password-free login

Key rotation is an important part of GitHub's overall security strategy. By regularly changing keys, GitHub can ensure that attacks are more difficult and that user data remains secure.

Source: www.bleepingcomputer.com

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS