The Hacker News

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present in .github/workflows/jira_issue.yml, which ran when a

بقلم The Hacker News

1 دقيقة قراءة
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

هل لديك أخبار لمشاركتها مع صناعة الفعاليات؟

أرسل بياناً صحفياً أو تلميحاً بقصة وتواصل مع آلاف المهنيين في مجال الفعاليات.

تواصل معنا→

المزيد في Cybersecurity, Cryptography & Digital Trust

رؤى ذات صلة