Firstpost
  • Home
  • Video Shows
    Vantage Firstpost America Firstpost Africa First Sports
  • World
    US News
  • Explainers
  • News
    India Opinion Cricket Tech Entertainment Sports Health Photostories
  • Asia Cup 2025
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
Trending:
  • Charlie Kirk shot dead
  • Nepal protests
  • Russia-Poland tension
  • Israeli strikes in Qatar
  • Larry Ellison
  • Apple event
  • Sunjay Kapur inheritance row
fp-logo
Github fixes high security flaw reported by Google Project Zero three months ago
Whatsapp Facebook Twitter
Whatsapp Facebook Twitter
Apple Incorporated Modi ji Justin Trudeau Trending

Sections

  • Home
  • Live TV
  • Videos
  • Shows
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Health
  • Tech/Auto
  • Entertainment
  • Web Stories
  • Business
  • Impact Shorts

Shows

  • Vantage
  • Firstpost America
  • Firstpost Africa
  • First Sports
  • Fast and Factual
  • Between The Lines
  • Flashback
  • Live TV

Events

  • Raisina Dialogue
  • Independence Day
  • Champions Trophy
  • Delhi Elections 2025
  • Budget 2025
  • US Elections 2024
  • Firstpost Defence Summit
  • Home
  • Tech
  • News & Analysis
  • Github fixes high security flaw reported by Google Project Zero three months ago

Github fixes high security flaw reported by Google Project Zero three months ago

FP Trending • November 27, 2020, 11:49:17 IST
Whatsapp Facebook Twitter

While Google described it as a ‘high severity’ bug, GitHub argued it was a ‘moderate security vulnerability’.

Advertisement
Subscribe Join Us
Add as a preferred source on Google
Prefer
Firstpost
On
Google
Github fixes high security flaw reported by Google Project Zero three months ago

Github has managed to fix a high severity security flaw that was reported to it by Google Project Zero around three months back. The bug affected GitHub’s developer workflow automation tool called Actions feature that according to Google Project Zero researcher Felix Wilhelm was extremely vulnerable to injection attacks, as per a report by ZDNet. While Google described it as a ‘high severity’ bug, GitHub argued it was a ‘moderate security vulnerability’. As per the report, Google Project Zero usually discloses any flaws it finds 90 days after reporting them. By 2 November, GitHib had exceeded Google’s one-off grace period of 14 days without fixing the flaw. [caption id=“attachment_8489671” align=“alignnone” width=“1280”] ![GitHub](https://images.firstpost.com/wp-content/uploads/2020/06/github-1280.jpg) GitHub[/caption] As per the report, a day before the disclosure deadline, GitHub told Google it would be disabling the vulnerable commands by November 2 and then requested an additional 48 hours. They asked this, not to fix the issue, but rather to notify customers and determine when they will look into it at a later date. Finally, after 104 days of reporting the issue to GitHub, Google published details of the bug. GitHub has finally gotten around to addressing the issue last week by disabling the feature’s old runner commands, “set-env” and “add-path”. Wilhelm had written in his bug report that the “set-env” was interesting because it can be used to define arbitrary environment variables as part of a workflow step. With GitHub having fixed the issue, Wilhelm too has updated his issue report to confirm that the matter has been resolved, the report added.

Tags
bug Github Google Project Zero set env
End of Article
Latest News
Find us on YouTube
Subscribe
End of Article

Top Stories

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

From governance to tourism, how Gen-Z protests have damaged Nepal

From governance to tourism, how Gen-Z protests have damaged Nepal

Did Russia deliberately send drones into Poland’s airspace?

Did Russia deliberately send drones into Poland’s airspace?

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

Charlie Kirk, shot dead in Utah, once said gun deaths are 'worth it' to save Second Amendment

From governance to tourism, how Gen-Z protests have damaged Nepal

From governance to tourism, how Gen-Z protests have damaged Nepal

Did Russia deliberately send drones into Poland’s airspace?

Did Russia deliberately send drones into Poland’s airspace?

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Netanyahu ‘killed any hope’ for Israeli hostages: Qatar PM after Doha strike

Top Shows

Vantage Firstpost America Firstpost Africa First Sports
Latest News About Firstpost
Most Searched Categories
  • Web Stories
  • World
  • India
  • Explainers
  • Opinion
  • Sports
  • Cricket
  • Tech/Auto
  • Entertainment
  • IPL 2025
NETWORK18 SITES
  • News18
  • Money Control
  • CNBC TV18
  • Forbes India
  • Advertise with us
  • Sitemap
Firstpost Logo

is on YouTube

Subscribe Now

Copyright @ 2024. Firstpost - All Rights Reserved

About Us Contact Us Privacy Policy Cookie Policy Terms Of Use
Home Video Shorts Live TV