Miami Indian Community - MiamiIndian.net
| | | | | | | | | | | |
 


 

GitHub fixes security flaw flagged by Google

Costa Rica,Science/Tech,Technology

Author : Indo Asian News Service

Technology, International, Science/Tech, National, Costa Rica Read Latest News and Articles

Share With Your Friends



Add an Article

View All Contributions

Add To My Favorite

Add A Picture

San Francisco, Nov 23 (IANS) Microsoft-owned open source code repository GitHub has finally fixed a security flaw spotted by Google months ago.

Google disclosed the details of the bug 104 days after it reported the issue to GitHub.

The fix was finally implemented on November 16, or two weeks after Google made the issue public, ZDNet reported on Monday.

The bug was reported by Google Project Zero, the company's security team that finds bugs in all popular software.

The "high severity" security bug was spotted in GitHub's Actions feature, a developer workflow automation tool.

"The big problem with this feature is that it is highly vulnerable to injection attacks," Google Project Zero researcher Felix Wilhelm wrote in the bug report.

"As the runner process parses every line printed to STDOUT looking for workflow commands, every Github action that prints untrusted content as part of its execution is vulnerable. In most cases, the ability to set arbitrary environment variables results in remote code execution as soon as another workflow is executed."

GitHub finally addressed the injection vulnerability by disabling the feature's old runner commands, "set-env" and "add-path," said the report.

--IANS

gb/vd


Copyright and Disclaimer: All news and images appearing in our news section, search engines and social media are provided by IANS. If you face any issues related to the content/images, please contact our news service provider directly. We are not liable/responsible for any content/images related to the news service provider.


Latest News

View More News


More News Articles

IPL 2024: All it needs is to win a couple of games and you are back in contention, says Rashid Khan

IPL 2024: All it needs is to win a couple of games and you are back in contention, says Rashid Khan

Aditi Rao Hydari's b'day wish for 'manicorn' Siddharth: 'Endless laughter, happiness'

Aditi Rao Hydari's b'day wish for 'manicorn' Siddharth: 'Endless laughter, happiness'

Why Vidya Malvade says she felt she would become 6 feet tall by end of 'Ruslaan' shoot