Vulnerabilities

GitHub rotates keys to mitigate impact of credential-exposing flaw

0

GitHub has rotated some keys in response to a security vulnerability that could be potentially exploited by attackers to gain access to credentials within production containers via environment variables.

This vulnerability tracked as CVE-2024-0200 can allow attackers to gain remote code execution on unpatched servers.

It was also patched on Tuesday in GitHub Enterprise Server (GHES) versions 3.8.13, 3.9.8, 3.10.5, and 3.11.3, and the company urges all customers to install the security update as soon as possible.

While allowing threat actors to gain access to environment variables of a production container, including credentials, successful exploitation requires authentication with an organization owner role.

While the organization owner role requirement is a significant mitigating factor and the vulnerability’s impact is limited to the researcher who found and reported the issue through GitHub’s Bug Bounty Program, GitHub’s Jacob DePriest says the credentials were still rotated according to security procedures and “out of an abundance of caution.”

Although most of the keys rotated by GitHub in December require no customer action, those using GitHub’s commit signing key and GitHub Actions, GitHub Codespaces, and Dependabot customer encryption keys will have to import the new public keys.

DePriest insists that the users must be regularly pulling the public keys from the API to ensure they are using the most current data from GitHub. This will also allow for seamless adoption of new keys in the future.

GitHub also fixed a second high-severity Enterprise Server command injection vulnerability (CVE-2024-0507) that would allow attackers using a Management Console user account with an editor role to escalate privileges.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

Ivanti zero-days exploited by multiple actors globally

Previous article

Russian ColdRiver hackers release custom malware

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *