logo

GitHub Bug Allowed Third-Party Apps to Gain Elevated Permissions

ID: 3d0db169-c315-5c6d-9847-774430952ce7

STIX ID: report--3d0db169-c315-5c6d-9847-774430952ce7

Feed Name: Aqua Security Blog

Threat Score
70/100

Date Published: 2022-06-20

Date Updated: 2026-04-26

...
...

A GitHub bug present from 2022-02-25 to 2022-03-02 allowed third-party GitHub Apps to generate scoped installation tokens with elevated permissions (e.g., write access instead of read), potentially enabling data loss, secret/credential leaks, or administrative actions across affected repositories; tokens were short-lived (up to one hour), GitHub patched the issue quickly and reported no evidence of exploitation, and organizations are advised to review installed apps, their permissions, and supply-chain access controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.