News Score: Score the News, Sort the News, Rewrite the Headlines

Weaponizing Dependabot: Pwn Request at its finest

TL;DR: Your trusty Dependabot (and other GitHub bots) might be an unwitting accomplice. Through "Confused Deputy" attacks, they can be tricked into merging malicious code. This doesn’t stop here. It can escalate to full command injection via crafted branch names and even bypass branch protection rules. Plus, we disclose two new TTPs to build upon previously known techniques. Introduction Ah, Dependabot! GitHub's built-in butler, tirelessly checks if your dependencies are fresh and, if not, prepa...

Read more at boostsecurity.io

© News Score  score the news, sort the news, rewrite the headlines