HomeSecurityResearcher managed to hack GitHub, exploiting 5 security flaws

Researcher managed to hack GitHub, exploiting 5 security flaws

Expert-Hacks-Private-Repositories-on-GitHub-by-Combining-5-Low-Severity-Bugs

The popular web code development and hosting platform, GitHub, recently launched a bug bounty program, motivating several researchers to search for errors in the platform's code repositories.

One of these researchers is Egor Homakov, who managed to gain access to private GitHub repositories using a combination of 5 low-severity flaws.

Individually, these flaws cannot be exploited to cause significant damage, but when combined, a high-severity vulnerability results.

The researcher notified GitHub about the vulnerability, which was promptly patched

Homakov was awarded $4,000 (€2,935), the largest reward offered by GitHub to date.

Additional technical details are available on Homakov's blog and Reddit.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS