supply-chain
Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking
High
Summary
A new vulnerability, dubbed ‘Cordyceps,’ has been identified within CI/CD workflows across numerous open-source projects, allowing unauthorized access and control over developer repositories. The flaws, primarily found in GitHub Actions YAML files, enable attackers to execute commands, steal credentials, and potentially compromise entire software supply chains. This widespread issue poses a significant risk to organizations utilizing these tools and their dependent systems.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data