The Hacker News

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present in .github/workflows/jira_issue.yml, which ran when a

By The Hacker News

1 min read
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Got news to share with the events industry?

Submit a press release or story tip and reach thousands of event professionals.

Get in touch→

More in Cybersecurity, Cryptography & Digital Trust

Related Insights