Back to directory
WRITEUP #282

Compromising ByteDance’s Rspack using GitHub Actions Vulnerabilities

OtherCI/CDPwn Request
byAdam Crosser
Program
ByteDance (Rspack)
Published
May 31, 2024
Added to HackDex
Jun 5, 2024
Read Full Writeuphttps://www.praetorian.com/blog/compromising-bytedances-rspack-github-actions-vulnerabilities/
RELATED WRITEUPS
Github Actions Exploitation: Dependabot
OtherCI/CD
GitHub Actions Exploitation: Self Hosted Runners
OtherCI/CD
Data Theft in Salesforce: Manipulating Public Links
OtherSOQL injection
When Certificates Fail: A Story of Bypassed MFA in Remote Access
Other2FA / MFA bypass
SSTI in Bug Bounty Program: The Time I Played with Handlebars and Broke Stuff
OtherSSTI

Built with ❤️ by Shubham Rawat