Skip to content
TrackPodcasts
technologyNov 23, 20208:54pending

Using GitHub Actions ? Be Aware of this High-Severity Injection Bug Found in GitHub Actions

About this episode

Felix Wilhelm of Google Project Zero found an injection Vulnerability affecting GitHub Actions and Workflow Commands specifically related to setting malicious environment variables by parsing STDOUT

Resources

https://github.blog/changelog/2020-10-01-github-actions-deprecating-set-env-and-add-path-commands/

https://bugs.chromium.org/p/project-zero/issues/detail?id=2070&can=2&q=&colspec=ID%20Type%20Status%20Priority%20Milestone%20Owner%20Summary&cells=ids

https://www.zdnet.com/article/google-to-github-times-up-this-unfixed-high-severity-security-bug-affects-developers/


Get every episode summarized

Each time The Backend Engineering Show with Hussein Nasser publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

No transcript yet

This episode has not been transcribed. Request it and it moves to the front of the queue.

Using GitHub Actions ? Be Aware of this High-Severity Injection Bug Found in GitHub Actions

The Backend Engineering Show with Hussein Nasser

0:00
8:54

More episodes

More from The Backend Engineering Show with Hussein Nasser

View all episodes →