GitHub has updated GPG keys due to a vulnerability that led to the leakage of environment variables.

GitHub has disclosed details regarding a vulnerability that allows access to the contents of environment variables exposed in containers used within the operational infrastructure. The vulnerability was identified by a participant in the Bug Bounty program seeking a reward for discovering security issues. This problem affects both the GitHub.com service and GitHub Enterprise Server (GHES) configurations running on user systems.

Log analysis and infrastructure audits revealed no evidence of the vulnerability being exploited in the past, except for the activity of the researcher who reported the issue. Nonetheless, the infrastructure has initiated the replacement of all encryption keys and credentials that could have been potentially compromised in the event of a malicious exploitation of the vulnerability. The internal key replacement resulted in some services being disrupted from December 27 to 29. GitHub administrators attempted to address the errors made during yesterday's key update, which affected customers.

Among other updates, the GPG key used for signing commits made through the GitHub web editor when accepting pull requests on the site or via the Codespace toolkit has been updated. The old key became inactive on January 16 at 11 PM Moscow time, and a new key has been in use since yesterday. Starting from January 23, all new commits signed with the old key will not be marked as verified on the GitHub site.

On January 16, public keys used for encrypting data sent by users via the API to GitHub Actions, GitHub Codespaces, and Dependabot were also updated. Users employing GitHub's public keys for local commit verification and data transmission encryption are advised to ensure they have updated their GitHub GPG keys and that their systems continue to function after the key replacement.

GitHub has already addressed the vulnerability on GitHub.com and released product updates for GHES 3.8.13, 3.9.8, 3.10.5, and 3.11.3, which note the fix for CVE-2024-0200 (insecure use of reflections leading to code execution or controlled methods on the client side). serverAn attack on local GHES installations could have been carried out by an attacker with an organizational owner account.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster