GitHub Apps access suspended installations" vulnerability

Post Reply
Shane1145
Posts: 1854
Joined: Wed Sep 25, 2024 2:31 pm

GitHub Apps access suspended installations" vulnerability

Post by Shane1145 »

The "GitHub Apps access suspended installations" vulnerability allows certain GitHub Apps to interact with suspended installations using scoped tokens, bypassing intended restrictions. This flaw risks unauthorized access to sensitive information, potentially compromising project security and data integrity.

https://hackerone.com/reports/2484635
Post Reply