GitHub rotates keys to mitigate impact of credential-exposing flaw
ID: 5773a965-a555-5883-a277-543a1fa3a131
STIX ID: report--5773a965-a555-5883-a277-543a1fa3a131
Feed Name: Bleeping Computer
GitHub patched a critical unsafe reflection vulnerability (CVE-2024-0200) that could allow authenticated organization owners to access environment variables — including credentials — in production containers and potentially achieve remote code execution; the company rotated potentially exposed keys and urged customers to install GHES updates. A separate high-severity command-injection bug (CVE-2024-0507) affecting the Management Console was also fixed; GitHub reports no evidence of prior exploitation and recommends importing new public keys where applicable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
