highLogic errorOther
Docker Secret Disclosure via GitHub Actions Cache Poisoning
- Payout
- $2k
- Protocol
- hyperledger
- Disclosed
- Apr 20, 2024
- Source
- hackerone
A GitHub Actions cache poisoning vulnerability was identified in the Hyperledger repository infrastructure. The flaw allowed unauthorized actors to modify shared build cache keys and execute arbitrary code within CI/CD pipeline steps. When downstream workflows …
Similar reports
- No close matches yet.
References
This report is already public and closed. Coin Buggie never publishes active or unpatched vulnerability data.