TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Flaw in GitHub OAuth logic allowed unrestricted access to private repositories

17 点作者 kailanb超过 7 年前
Many just received this email from GitHub support: --<p>GitHub has discovered an error in the logic used to enforce OAuth App access restrictions, which restrict OAuth integration access to an organization&#x27;s private repositories. In certain situations, when a member of an organization granted access to a third-party OAuth integration, that integration could have been given more access to some of your organization’s repositories than we intended to allow.<p>When an organization enables OAuth App access restrictions, GitHub generally limits OAuth integration access to private repositories. This error in OAuth App access restrictions allowed third-party OAuth integrations, such as continuous integration providers, the same access permissions to certain private repositories within an organization as the user who implemented the integration had, provided they had authorized the integration for a scope capable of interacting with repositories.<p>-- Full email: https:&#x2F;&#x2F;gist.github.com&#x2F;kailan&#x2F;9f37ec2cd76314f945dda65e5beab241

1 comment

graystevens超过 7 年前
Clickable link: <a href="https:&#x2F;&#x2F;gist.github.com&#x2F;kailan&#x2F;9f37ec2cd76314f945dda65e5beab241" rel="nofollow">https:&#x2F;&#x2F;gist.github.com&#x2F;kailan&#x2F;9f37ec2cd76314f945dda65e5beab...</a><p>Very interesting. I wonder if any private organisations setup a pseudo&#x2F;canary repositories, that when pulled triggered an alarm? Or simply contained some monitored API keys or credentials to spot any activity&#x2F;Insider threats.<p>Might be a neat idea for those businesses that are concerned about their private repos (either cloud hosted or self hosted).<p>May have picked up if anyone was able to exploit this.