wiz-sec / open-cvdb

An open project to list all publicly known cloud vulnerabilities and CSP security issues
https://cloudvulndb.org
Creative Commons Attribution 4.0 International
303 stars 61 forks source link

[Contribution] Add Bazel supply chain issue #275

Open korniko98 opened 6 months ago

korniko98 commented 6 months ago

Summary (give a brief description of the issue)

Cycode discovered a CI/CD misconfiguration in the Bazel repo, which if exploited could have allowed an attacker to enact a supply chain attack against all Bazel users, which includes Google themselves and probably GCP (https://bazel.build/community/users#google).

References (provide links to blogposts, etc.)

https://cycode.com/blog/cycode-discovers-a-supply-chain-vulnerability-in-bazel/