Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedbsnowflakeconnectornet repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials. The issue was present in .githubworkflowsjiraissue.yml, which ran when a.π Read more.
π Via "The Hacker News"
----------
ποΈ Seen on @cibsecurity