Home / Companies / Sysdig / Blog / Post Details
Content Deep Dive

Dangerous by default: Insecure GitHub Actions found in MITRE, Splunk, and other open source repositories

Blog post from Sysdig

Post Details
Company
Date Published
Author
Stefano Chierici
Word Count
2,403
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

The Sysdig Threat Research Team (TRT) identified critical security vulnerabilities in GitHub Actions workflows across various high-profile open source projects, such as those maintained by MITRE, Splunk, and the Spotipy Python library. These vulnerabilities primarily revolve around the misuse of the pull_request_target event, which can expose repository secrets and grant high-privilege access to attackers when handling pull requests from untrusted sources. Despite the availability of well-documented methods for securing CI/CD workflows, many projects remain susceptible due to a lack of maturity in implementing security best practices. The article highlights specific instances where these vulnerabilities were exploited to exfiltrate secrets, and it offers recommendations for mitigating such risks, including splitting workflows into privileged and unprivileged components, restricting GITHUB_TOKEN permissions, and using runtime threat detection tools like Falco Actions. The Sysdig TRT continues to collaborate with affected organizations to address these issues and improve the security posture of open source projects.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 17 1,161 159 70 +7%
Real-time 1 4,075 1,042 211 +22%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.