Harden-Runner to agent bezpieczeństwa CI/CD działający jak EDR dla runnerów GitHub Actions. Przed wersją 2.14.2 zidentyfikowano podatność w GitHub Action Harden-Runner (Community Tier), która umożliwia wychodzącym połączeniom sieciowym omijanie logowania audytowego. W szczególności ruch wychodzący używający socket system calls sendto, sendmsg i sendmmsg może ominąć detekcję i logowanie przy użyciu egress-policy: audit. Podatność naprawiono w wersji 2.14.2.
▸ Pokaż oryginał (EN)
Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security vulnerability has been identified in the Harden-Runner GitHub Action (Community Tier) that allows outbound network connections to evade audit logging. Specifically, outbound traffic using the sendto, sendmsg, and sendmmsg socket system calls can bypass detection and logging when using egress-policy: audit. This vulnerability is fixed in 2.14.2.
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XStepsecurity Harden Runner
APPStepsecurity< 2.14.2
Powiązane podatności
Harden-Runner to agent bezpieczeństwa CI/CD działający jak EDR dla GitHub Actions runners. W wersji 2.15.1 i w...
Harden-Runner to agent zabezpieczający CI/CD działający jak EDR dla GitHub Actions runners. W wersjach 2.15.1 ...