Security News > 2020 > November > Google Discloses Details of GitHub Actions Vulnerability

Google Discloses Details of GitHub Actions Vulnerability
2020-11-05 04:40

Details on a vulnerability impacting GitHub Actions were made public this week by Google, following a 104-day disclosure deadline.

The bug was identified by security researcher Felix Wilhelm of Google Project Zero, who reported it to GitHub on July 21.

GitHub has assigned the issue a moderate severity rating, but Google Project Zero says it's high severity.

"As the runner process parses every line printed to STDOUT looking for workflow commands, every Github action that prints untrusted content as part of its execution is vulnerable. In most cases, the ability to set arbitrary environment variables results in remote code execution as soon as another workflow is executed," Wilhelm notes.

The issue, GitHub confirms, is that paths and environment variables can be injected into workflows that log untrusted data to stdout, all without the intention of the workflow author.


News URL

http://feedproxy.google.com/~r/Securityweek/~3/TIMAYa1IBo0/google-discloses-details-github-actions-vulnerability

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 141 994 4924 2874 1623 10415
Github 12 3 42 30 15 90