View Repo and Title of Any Private Check Run vulnerability

Post Reply
Shane1145
Posts: 1825
Joined: Wed Sep 25, 2024 2:31 pm

View Repo and Title of Any Private Check Run vulnerability

Post by Shane1145 »

This vulnerability allows unauthorized users to view details about private check runs, potentially exposing repository information and titles that are intended to be confidential. This exposure could compromise sensitive project data and provide insight into workflows that should remain private. Proper access controls and authorization checks are necessary to mitigate this issue.


https://hackerone.com/reports/2210179
Post Reply