Write-ups
Check The Published Writeups
WDB | Title | Tags | Programs | Authors | Type | Publication | Added |
---|---|---|---|---|---|---|---|
1667 | Vulnerable GitHub Actions Workflows Part 1: Privilege Escalation Inside Your CI/CD Pipeline | Privilege escalation CI/CD | GitHub | Noam Dotan | Bug Bounty | 2022-04-04 | 2023-06-13 |
1585 | Vulnerable GitHub Actions Workflows Part 2: Actions That Open the Door to CI/CD Pipeline Attacks | Privilege escalation CI/CD | NA | Noam Dotan | Bug Bounty | 2022-05-02 | 2023-06-13 |
1141 | Google & Apache Found Vulnerable to GitHub Environment Injection | Privilege escalation CI/CD | Google Apache | Noam Dotan | Bug Bounty | 2022-09-01 | 2023-06-13 |
1098 | Attackers Can Bypass GitHub Required Reviewers to Submit Malicious Code | Authorization flaw Logic flaw | GitHub | Noam Dotan | Bug Bounty | 2022-09-08 | 2023-06-13 |
750 | Novel Pipeline Vulnerability Discovered; Rust Found Vulnerable | Supply chain attack | GitHub Rust | Noam Dotan | Bug Bounty | 2022-12-01 | 2023-06-13 |