logo

GitHub rotates keys to mitigate impact of credential-exposing flaw

ID: 5773a965-a555-5883-a277-543a1fa3a131

STIX ID: report--5773a965-a555-5883-a277-543a1fa3a131

Feed Name: Bleeping Computer

Threat Score
50/100

Date Published: 2024-01-16

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

GitHub patched a critical unsafe reflection vulnerability (CVE-2024-0200) that could allow authenticated organization owners to access environment variables — including credentials — in production containers and potentially achieve remote code execution; the company rotated potentially exposed keys and urged customers to install GHES updates. A separate high-severity command-injection bug (CVE-2024-0507) affecting the Management Console was also fixed; GitHub reports no evidence of prior exploitation and recommends importing new public keys where applicable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.