QID 994869
Date Published: 2023-08-17
QID 994869: GO (Go) Security Update for github.com/woodpecker-ci/woodpecker (GHSA-4gcf-5m39-98mc)
An attacker can post malformed webhook data witch lead to an update of the repository data that can e.g. allow the takeover of an repo. This is only critical if the CI is configured for public usage and connected to a forge witch is also in public usage.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-4gcf-5m39-98mc for updates and patch information.
Vendor References
- GHSA-4gcf-5m39-98mc -
github.com/advisories/GHSA-4gcf-5m39-98mc
CVEs related to QID 994869
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4gcf-5m39-98mc | github.com/woodpecker-ci/woodpecker |
|