漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
In the Eclipse Theia Website repository, the GitHub Actions workflow .github/workflows/preview.yml used pull_request_target trigger while checking out and executing untrusted pull request code. This allowed any GitHub user to execute arbitrary code in the repository's CI environment with access to repository secrets and a GITHUB_TOKEN with extensive write permissions (contents:write, packages:write, pages:write, actions:write). An attacker could exfiltrate secrets, publish malicious packages to the eclipse-theia organization, modify the official Theia website, and push malicious code to the repository.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vulnerability Type
从非可信控制范围包含功能例程
Vulnerability Title
Eclipse Theia - Website 安全漏洞
Vulnerability Description
Eclipse Theia - Website是Eclipse基金会的一个开发环境框架。 Eclipse Theia - Website存在安全漏洞,该漏洞源于GitHub Actions工作流使用pull_request_target触发器执行不受信任的代码,可能导致任意代码执行、凭据泄露和恶意代码推送。
CVSS Information
N/A
Vulnerability Type
N/A