Connect with us
X
Categories:

Technology

GitHub Actions workflow flaws gave applications like Logstash write access

Published

on

GitHub Actions workflow flaws gave applications like Logstash write access
Share this post:

Malicious builds and wider infrastructural compromise were worst-case scenarios.

Security researchers have identified multiple workflows in popular continuous integration and development (CI/CD) service GitHub Actions that are vulnerable to command execution.

A research team from dating platform Tinder crafted an automation script that unearthed flaws that enabled the exfiltration of secrets that provide write access to various open source GitHub repositories, including Elastic’s Logstash.

A blog post documenting the findings was penned by Rojan Rijal, Johnny Nipper, and Tanner Emek – respectively red teamer, senior product security manager, and engineering manager at Tinder.

The trio told Daily Swig that “in the worst case scenario, you can exploit a vulnerable workflow to retrieve the GITHUB_TOKEN value”, which has read/write access to the repository by default. “This can be used to push a malicious build against users and perform supply chain related exploits.”

If more sensitive access secrets within the workflow such as AWS credentials, API Keys, or service credentials were exposed, “this could lead to a compromise of a company’s infrastructure”, they added.

The most common cause of vulnerabilities was unsafe user inputs in run scripts. The researchers also found many examples where pull_request_target was misused, which among other things could bypass a 2019 fix for an issue related to the use of event handlers in forked repositories.

The research focused on projects with vulnerability disclosure policies, with validated vulnerabilities responsibly reported to projects. Elastic’s security team quickly deactivated the vulnerable workflow and confirmed no abuse had occurred, said the researchers.

GitHub Workflow Auditor

Tinder Security Labs has open sourced the tool used for the research. GitHub Workflow Auditor checks workflows for unsafe user inputs, malicious commits, and secrets.

Given the limitations of comparable, existing tools, the authors told Daily Swig that they “focused on covering most vulnerability cases in GitHub Actions as well as efficiency. As such, we allow organizations to scan all of their repositories at once by providing a GitHub API key. This reduces time and effort for security teams”.

RECOMMENDED  Your daily horoscope for Sunday, September 4, 2022

The tool also addressed a supply chain risk posed by workflows running actions from old GitHub accounts. “In such cases, attackers can claim the account and push malicious actions allowing them to get access to the repository and its workflows,” the researchers explained. “This specific case was not covered by the tools that we tested.”

They added: “Our goal at Tinder Labs is to identify high impact vulnerabilities in a wide array of technologies which have global impact. As we research other technologies, you can expect to see more findings and tools from us in the future.”

Mitigations

The researchers urged developers to properly sanitize user inputs in GitHub Actions and mitigate attacks by limiting GitHub Tokens’ access scope.

GitHub Security Lab has, meanwhile, previously recommended that pull_request_target only be used when developers “need the privileged context of the target repo” in their workflow.

Tinder Security Labs’ findings follow the disclosure in March of misconfigured GitHub Actions workflows that caused critical flaws in dozens of repos, and a GitHub Actions patch in January for a code review safeguard bypass.


Get More Stories Like This On: Facebook: @AllNaijaEntertainment, Twitter: @AllNaijaEntertainment
General7 hours ago

Skylar Grey – Everything I Need [LYRICS]

General7 hours ago

[Music] Diddy – Dirty Money – “Coming Home” Feat. Skylar Grey

General7 hours ago

Diddy – Dirty Money – “Coming Home” Feat. Skylar Grey [LYRICS]

General7 hours ago

[Music] African China – Amen

General7 hours ago

[Music] African China – Baba God

General7 hours ago

African China – Baba God [LYRICS]

General7 hours ago

Machine Gun Kelly (MGK) “Home” Feat X Ambassadors & Bebe Rexha [LYRICS]

General7 hours ago

Passenger – Let Her Go [LYRICS]

General7 hours ago

[Music] Eminem – “No Love” Feat. Lil Wayne

General8 hours ago

Eminem – “No Love” Feat. Lil Wayne [LYRICS]

Music8 hours ago

[Music] Tatiana Manaois – Buzz Kill

General8 hours ago

Tatiana Manaois – Buzz Kill [LYRICS]

General8 hours ago

James Blunt – Goodbye My Lover [LYRICS]

General8 hours ago

Major Lazer – “Particula” Feat. Nasty C , Ice Prince, Patoranking & Jidenna [LYRICS]

General8 hours ago

James Blunt – You’re Beautiful [LYRICS]

General8 hours ago

Justin Timberlake – Mirrors [LYRICS]

General8 hours ago

[Music] Darey – “Pray For Me” feat. Soweto Gospel Choir

General8 hours ago

Eminem – “Love The Way You Lie” Feat. Rihanna [LYRICS]

General8 hours ago

Goldlink ft. Miguel – Got Friends [LYRICS]

General8 hours ago

Sia – I’m Still Here [LYRICS]

General8 hours ago

Yo Gotti ft. Nicki Minaj – Rake It Up [LYRICS]

General8 hours ago

Shane McMahon – Here Comes The Money [LYRICS]

General9 hours ago

Journey – Faithfully [LYRICS]

General9 hours ago

[Music] Journey – Faithfully

General9 hours ago

Eminem – Not Afraid [LYRICS]

General9 hours ago

[Music] Journey – Don’t Stop Believin’

General9 hours ago

Journey – Don’t Stop Believin’ [LYRICS]

General9 hours ago

21 Savage – Bank Account [LYRICS]

General9 hours ago

Demi Lovato – Sober [LYRICS]

General9 hours ago

Beyonce ft. Jay-Z – Apeshit [LYRICS]

General9 hours ago

Nasty C ft. ASAP Ferg – King [LYRICS]

General10 hours ago

Lil Wayne – Uproar [LYRICS]

Ed Sheeran
Lyrics10 hours ago

Ed Sheeran – Perfect [LYRICS]

General10 hours ago

[Music] Mo’Hits All Star – Close To You

General10 hours ago

Lil Dicky ft. Chris Brown – Freaky Friday [LYRICS]

Michael Jackson
Lyrics10 hours ago

Michael Jackson – Stranger In Moscow [LYRICS]

General10 hours ago

[Music] Celine Dion – I Drove All Night

General10 hours ago

Celine Dion – I Drove All Night [LYRICS]

General10 hours ago

Tatiana Manaois – Hey Little Lady [LYRICS]

Music10 hours ago

[Music] Tatiana Manaois – Live Better

Gnash (singer)
Music4 days ago

[Music] Gnash Ft Olivia O’Brien – I Hate you, I Love you

John Legend
Music1 day ago

[INSTRUMENTAL] John Legend – All Of Me

Alan Walker
Music5 days ago

Alan Walker – Faded [INSTRUMENTAL]

21 Savage
Music2 days ago

[Video] 21 Savage ft. Offset & Metro Boomin – Rap Saved Me

Wiz Khalifa
Music4 days ago

[Instrumental] Wiz Khalifa – See You Again ft. Charlie Puth

General7 days ago

[Music] Sapientdream – Pastlives

Salvation Ministry Choir Amen
Lyrics2 days ago

Salvation Ministry Choir – Amen [LYRICS]

General7 days ago

[Music] Don Omar – Danza Kuduro (feat. Lucenzo)

General5 days ago

[Music] The Chainsmokers – ‘Don’t Let Me Down’ Feat. Daya

General7 days ago

Ladé – Adulthood Anthem (Adulthood Na Scam) [Lyrics]

General7 days ago

[Music] Timbaland – Apologize ft. OneRepublic

Powfu (singer)
Music4 days ago

[Music] Powfu – Death Bed (Coffee for Your Head) Feat. Beabadoobee

General5 days ago

[Music] Wyclef Jean – “Sweetest Girl (Dollar Bill)” Feat. Akon, Lil Wayne, Niia

General3 days ago

[Music] Zayn Malik – Entertainer

Wiz Khalifa - See You Again ft. Charlie Puth
Music4 days ago

[Music] Wiz Khalifa – See You Again ft. Charlie Puth

Music3 days ago

[Music] Exalted Tribe (HICC) – We Dey Halla

Anna Kendrick
Music4 days ago

[Music] Anna Kendrick – Cups (Pitch Perfect’s “When I’m Gone”)

General7 hours ago

[Music] Diddy – Dirty Money – “Coming Home” Feat. Skylar Grey

General1 day ago

[Music] John Legend – Love Me Now

Right Said Fred
Music4 days ago

[Music] Right Said Fred – Stand Up (For the Champions)

Salvation Ministries Mass Choir
Music2 days ago

[Music] Salvation Ministries Choir – Chioma Me Eh(Good God)

General12 hours ago

[Music] Celine Dion – If That’s What It Takes

Salvation Ministries Mass Choir
Lyrics2 days ago

Salvation Ministries Choir – Chioma Me Eh(Good God) [LYRICS]

General12 hours ago

[Music] P!nk – Try

General6 days ago

[Music] Shaggy – Strength Of A Woman

General2 days ago

[Music] Jaden Smith – Goku

Music4 days ago

[Music] Wiz Khalifa – See You Again (Remix) Feat Charlie Puth, Eminem, Tyga, & Chris Brown

R. Kelly
Music4 days ago

[Music] R. Kelly – World’s Greatest

General1 day ago

Magic! — Rude [LYRICS]

General9 hours ago

[Music] Journey – Don’t Stop Believin’

General6 days ago

[Music] Justin Bieber – Love Me

General2 days ago

[Music] Cardi B – Bartier Cardi ft. 21 Savage

General7 days ago

[Music] Lionel Richie – Angel

General3 days ago

[Music] Tyga ft. Offset – Taste

General13 hours ago

[Music] P!nk – “Just Give Me A Reason” Feat. Nate Ruess

General7 days ago

[Music] BIG SHAQ – Man’s Not Hot

General3 days ago

[Music] 21 Savage ft. Offset & Metro Boomin – Rap Saved Me

General7 days ago

[Music] Shayne Ward – Breathless

General6 days ago

[Music] Post Malone – Candy Paint

General5 days ago

[Music] R Kelly – When A Woman Loves

ANE Billboard Hots



Join "ANE sabi" clique

Don't miss a thing, get ogbonge ANE latest updates to fuel your conversation daily.