The Hacker News

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present in .github/workflows/jira_issue.yml, which ran when a

作者 The Hacker News

1 分钟阅读
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

有活动行业的新闻要分享吗?

提交新闻稿或信息,触达数千名活动行业专业人士。

联系我们→

更多Cybersecurity, Cryptography & Digital Trust相关内容

相关洞察