GitLab's Perfect 10 Flaw Exposes Secrets
A maximum-severity path traversal bug in GitLab's repository commits API lets unauthenticated attackers read arbitrary files, and probes are already underway.
3 results for “ci/cd”
A maximum-severity path traversal bug in GitLab's repository commits API lets unauthenticated attackers read arbitrary files, and probes are already underway.
A GitHub Actions workflow flaw in Snowflake's connector repo allowed crafted issues to execute commands with exposed Jira credentials.
A sophisticated supply chain attack used legitimate GitHub pipelines to push malicious code via the AsyncAPI npm namespace.