Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials.
The issue was present in .github/workflows/jira_issue.yml, which ran when a
from The Hacker News https://ift.tt/E4g96cO
from The Hacker News https://ift.tt/E4g96cO