SecOpsNews / news

RSS items as GitHub Issues for the discerning engineering leader or security professional
MIT License
38 stars 0 forks source link

[HackerNews] GitHub Vulnerability 'ArtiPACKED' Exposes Repositories to Potential Takeover #32407

Open github-actions[bot] opened 2 months ago

github-actions[bot] commented 2 months ago

A newly discovered attack vector in GitHub Actions artifacts dubbed ArtiPACKED could be exploited to take over repositories and gain access to organizations' cloud environments. "A combination of misconfigurations and security flaws can make artifacts leak tokens, both of third party cloud services and GitHub tokens, making them available for anyone with read access to the repository to consume,

https://thehackernews.com/2024/08/github-vulnerability-artipacked-exposes.html