Critical GitHub Attack
GitHub遭遇复杂供应链攻击,影响数万仓库。攻击最初针对“tj-actions/changed-files”工具,后追溯至“reviewdog/action-setup@v1”漏洞。CISA确认已修复漏洞(版本46.0.1),但潜在影响巨大。 2025-3-20 15:14:23 Author: www.schneier.com(查看原文) 阅读量:16 收藏

Critical GitHub Attack

This is serious:

A sophisticated cascading supply chain attack has compromised multiple GitHub Actions, exposing critical CI/CD secrets across tens of thousands of repositories. The attack, which originally targeted the widely used “tj-actions/changed-files” utility, is now believed to have originated from an earlier breach of the “reviewdog/action-setup@v1” GitHub Action, according to a report.

[…]

CISA confirmed the vulnerability has been patched in version 46.0.1.

Given that the utility is used by more than 23,000 GitHub repositories, the scale of potential impact has raised significant alarm throughout the developer community.

Posted on March 20, 2025 at 11:14 AM0 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.


文章来源: https://www.schneier.com/blog/archives/2025/03/critical-github-attack.html
如有侵权请联系:admin#unsafe.sh