GitHub Rotates Keys After High-Severity Vulnerability Exposes Credentials
ID: d9f66454-c847-556e-8eaa-3d5c55ec1717
STIX ID: report--d9f66454-c847-556e-8eaa-3d5c55ec1717
Feed Name: The Hacker News
GitHub disclosed and fixed a high-severity "unsafe reflection" vulnerability (CVE-2024-0200, CVSS 7.2) that could allow access to credentials in a production container and rotated potentially exposed keys (including commit signing, Actions, Codespaces, and Dependabot keys); GHES patches and versions are provided. A separate high-severity issue (CVE-2024-0507, CVSS 6.5) that could enable privilege escalation via command injection was also addressed. GitHub reports no evidence of exploitation and urged affected users to import rotated keys.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
