A simple CodeBuild flaw put every AWS environment at risk
This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).
Security researchers at Wiz discovered a critical vulnerability in AWS CodeBuild that could have enabled complete takeover of AWS GitHub repositories and affected every AWS environment globally. The flaw, dubbed CodeBreach, stemmed from unanchored regex patterns in webhook filters that were supposed to protect against untrusted
•7m read time• From go.theregister.com
Table of contents
Breaking the code(build)Poking around the CI pipelineCreating a repo admin out of thin airSort: