Unauthorized Access to Private Repository NWO via Deploy Key in Internal LFS API

Post Reply
Shane1145
Posts: 1854
Joined: Wed Sep 25, 2024 2:31 pm

Unauthorized Access to Private Repository NWO via Deploy Key in Internal LFS API

Post by Shane1145 »

This vulnerability allows unauthorized viewing of private repository details, including the NWO (Namespace With Owner), through improper access in the internal LFS API. Exploiting this flaw could expose sensitive data tied to repository deployment keys, compromising repository security.


https://hackerone.com/reports/2469713
Post Reply