GitHub Bug Allowed Third-Party Apps to Gain Elevated Permissions
ID: 3d0db169-c315-5c6d-9847-774430952ce7
STIX ID: report--3d0db169-c315-5c6d-9847-774430952ce7
Feed Name: Aqua Security Blog
A GitHub bug present from 2022-02-25 to 2022-03-02 allowed third-party GitHub Apps to generate scoped installation tokens with elevated permissions (e.g., write access instead of read), potentially enabling data loss, secret/credential leaks, or administrative actions across affected repositories; tokens were short-lived (up to one hour), GitHub patched the issue quickly and reported no evidence of exploitation, and organizations are advised to review installed apps, their permissions, and supply-chain access controls.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
