MEDIUM🇬🇧 English

CVE-2026-25598

CVSS 6.3v4.0pub. 2026-02-09upd. 2026-02-28

Harden-Runner to agent bezpieczeństwa CI/CD działający jak EDR dla runnerów GitHub Actions. Przed wersją 2.14.2 zidentyfikowano podatność w GitHub Action Harden-Runner (Community Tier), która umożliwia wychodzącym połączeniom sieciowym omijanie logowania audytowego. W szczególności ruch wychodzący używający socket system calls sendto, sendmsg i sendmmsg może ominąć detekcję i logowanie przy użyciu egress-policy: audit. Podatność naprawiono w wersji 2.14.2.

Pokaż oryginał (EN)

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security vulnerability has been identified in the Harden-Runner GitHub Action (Community Tier) that allows outbound network connections to evade audit logging. Specifically, outbound traffic using the sendto, sendmsg, and sendmmsg socket system calls can bypass detection and logging when using egress-policy: audit. This vulnerability is fixed in 2.14.2.

CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Stepsecurity Harden Runner

    APP
    Stepsecurity
    < 2.14.2
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
CI/CD
CWE
Referencje

Powiązane podatności

CVE-2026-32946MEDIUM4.6ten sam produkt

Harden-Runner to agent bezpieczeństwa CI/CD działający jak EDR dla GitHub Actions runners. W wersji 2.15.1 i w...

CVE-2026-32947MEDIUM4.6ten sam produkt

Harden-Runner to agent zabezpieczający CI/CD działający jak EDR dla GitHub Actions runners. W wersjach 2.15.1 ...