GHSA-rq5c-hvw6-8pr7

    Dashboard / Vulnerabilities / GHSA-rq5c-hvw6-8pr7

    GHSA-rq5c-hvw6-8pr7

    Published: 29 Aug 2023Last Modified: 8 Nov 2023

    Summary: Improper log output when using GitHub Status Notifications in spinnaker

    Details: ### Impact ONLY IMPACTS those use GitHub Status Notifications Log output when updating GitHub status is improperly set to FULL always. It's recommended to apply the patch and rotate the GitHub token used for github status notifications. Given that this would output github tokens to a log system, the risk is slightly higher than a "low" since token exposure could grant elevated access to repositories outside of control. If using READ restricted tokens, the exposure is such that the token itself could be used to access resources otherwise restricted from reads. ### Patches Patch is in progress. https://github.com/spinnaker/echo/pull/1316 ### Workarounds Disable GH Status Notifications. Filter your logs for Echo log data. Use read-only tokens that are limited in scope. ### References sig-security in slack: https://spinnakerteam.slack.com/archives/CFN8F5UR2

    Affected packages

    Package

    Name: github.com/spinnaker/spinnaker

    Purl: pkg:golang/github.com/spinnaker/spinnaker

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-rq5c-hvw6-8pr7 | CVE-DB