🚀 DevOps Certified Professional
📅 Starting: 1st of Every Month 🤝 +91 8409492687 | 🤝 +1 (469) 756-6329 🔍 Contact@DevOpsSchool.com

GitHub fixes security flaw flagged by Google

GitHub

Upgrade & Secure Your Future with DevOps, SRE, DevSecOps, MLOps!

We spend hours on Instagram and YouTube and waste money on coffee and fast food, but won’t spend 30 minutes a day learning skills to boost our careers.
Master in DevOps, SRE, DevSecOps & MLOps!

Learn from Guru Rajesh Kumar and double your salary in just one year.


Get Started Now!

Source:-https://www.expresscomputer.in

Microsoft-owned open source code repository GitHub has finally fixed a security flaw spotted by Google months ago.

Google disclosed the details of the bug 104 days after it reported the issue to GitHub.

The fix was finally implemented on November 16, or two weeks after Google made the issue public, ZDNet reported on Monday.

The bug was reported by Google Project Zero, the company’s security team that finds bugs in all popular software.

The “high severity” security bug was spotted in GitHub’s Actions feature, a developer workflow automation tool.

“The big problem with this feature is that it is highly vulnerable to injection attacks,” Google Project Zero researcher Felix Wilhelm wrote in the bug report.

“As the runner process parses every line printed to STDOUT looking for workflow commands, every Github action that prints untrusted content as part of its execution is vulnerable. In most cases, the ability to set arbitrary environment variables results in remote code execution as soon as another workflow is executed.”

GitHub finally addressed the injection vulnerability by disabling the feature’s old runner commands, “set-env” and “add-path,” said the report.

 

Subscribe
Notify of
guest


This site uses Akismet to reduce spam. Learn how your comment data is processed.

0 Comments
Oldest
Newest Most Voted
Inline Feedbacks
View all comments
0
Would love your thoughts, please comment.x
()
x