logo

GitHub Rotates Keys After High-Severity Vulnerability Exposes Credentials

ID: d9f66454-c847-556e-8eaa-3d5c55ec1717

STIX ID: report--d9f66454-c847-556e-8eaa-3d5c55ec1717

Feed Name: The Hacker News

Threat Score
60/100

Date Published: 2024-01-17

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

GitHub disclosed and fixed a high-severity "unsafe reflection" vulnerability (CVE-2024-0200, CVSS 7.2) that could allow access to credentials in a production container and rotated potentially exposed keys (including commit signing, Actions, Codespaces, and Dependabot keys); GHES patches and versions are provided. A separate high-severity issue (CVE-2024-0507, CVSS 6.5) that could enable privilege escalation via command injection was also addressed. GitHub reports no evidence of exploitation and urged affected users to import rotated keys.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.