City
Epaper

GitHub fixes security flaw flagged by Google

By IANS | Updated: November 23, 2020 20:50 IST

San Francisco, Nov 23 Microsoft-owned open source code repository GitHub has finally fixed a security flaw spotted by ...

Open in App

San Francisco, Nov 23 Microsoft-owned open source code repository GitHub has finally fixed a security flaw spotted by Google months ago.

Google disclosed the details of the bug 104 days after it reported the issue to GitHub.

The fix was finally implemented on November 16, or two weeks after Google made the issue public, ZDNet reported on Monday.

The bug was reported by Google Project Zero, the company's security team that finds bugs in all popular software.

The "high severity" security bug was spotted in GitHub's Actions feature, a developer workflow automation tool.

"The big problem with this feature is that it is highly vulnerable to injection attacks," Google Project Zero researcher Felix Wilhelm wrote in the bug report.

"As the runner process parses every line printed to STDOUT looking for workflow commands, every Github action that prints untrusted content as part of its execution is vulnerable. In most cases, the ability to set arbitrary environment variables results in remote code execution as soon as another workflow is executed."

GitHub finally addressed the injection vulnerability by disabling the feature's old runner commands, "set-env" and "add-path," said the report.

( With inputs from IANS )

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

InternationalUnion MoS Kirti Vardhan Singh attends Sharm El-Sheikh Peace Summit, reaffirms India's support for Gaza peace plan and two-state solution

Entertainment"Will it recover money and make profit?" Ramesh Sippy recalls doubts over 'Sholay' before release

InternationalMP-IDSA-Sichuan University High Level Track-2 Dialogue to be held October 15-16

InternationalIndia welcomes landmark Gaza Peace Agreement, reaffirms commitment to dialogue and diplomacy

CricketICC Women's WC: SA skipper Wolvaardt rues underwhelming top-order show after win, Bangladesh skipper Nigar expresses pride in team's fight

Technology Realted Stories

TechnologyCEA draws up Rs 6.4 lakh crore green plan for evacuating hydropower from Brahmaputra

TechnologyEPFO members can now withdraw up to 100 pc of ‘eligible balance’ in PF account

TechnologyAndhra Pradesh emerging as leader in green energy: CM

TechnologySurat Municipal Corporation to list Gujarat’s first green bond on NSE on Oct 16

TechnologyGEF, UNDP to help India transition to a circular economy in electronics sector