wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
303 stars 61 forks source link

[Contribution] Azure Pipelines runner images supply chain vector #263

Open korniko98 opened 8 months ago

korniko98 commented 8 months ago

Summary (give a brief description of the issue)

A misconfiguration in one of GitHub's own repos could have (theoretically) allowed an attacker to modify the official GitHub and Azure Pipelines runner images.

References (provide links to blogposts, etc.)

https://adnanthekhan.com/2023/12/20/one-supply-chain-attack-to-rule-them-all/