Back to directory
WRITEUP #88

ArtiPACKED: Hacking Giants Through a Race Condition in GitHub Actions Artifacts

Race ConditionCI/CD
by@yaronavital(Yaron Avital)
Program
GitHubGoogle (Firebase)MicrosoftAWSRed HatCanonical (Ubuntu Adsys)OWASP
Published
Aug 13, 2024
Added to HackDex
Aug 22, 2024
Read Full Writeuphttps://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/
RELATED WRITEUPS
Revival Hijack – PyPI hijack technique exploited in the wild, puts 22K packages at risk
AI / LLMCI/CD
Github Actions Exploitation: Dependabot
OtherCI/CD
Race Condition About The User Version and Ignored
Race ConditionPayment bypass
Beyond the Limit: Expanding single-packet race condition with a first sequence sync for breaking the 65,535 byte limit
Race Condition
GitHub Actions Exploitation: Self Hosted Runners
OtherCI/CD

Built with ❤️ by Shubham Rawat