
DEF CON 32 - Your CI CD Pipeline Is Vulnerable, But It's Not Your Fault - Elad Pticha, Oreen Livni
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 25:47
[GitHub Actions pipelines are vulnerable to command injection due to untrusted user inputs and third-party custom actions, even when the pipeline itself appears secure. This vulnerability can lead to full repository compromise and exposure of sensitive credentials.]2:59
Key Takeaways:
• Command injection in GitHub Actions occurs when user-controlled inputs (e.g., issue titles) are directly used in commands without sanitization, allowing attackers to exfiltrate secrets 10:15-11:19.
• Custom actions introduce supply chain risks: vulnerable dependencies in third-party actions can be exploited to compromise entire pipelines, even if the user code is clean 14:55-15:31.
• The Bazel project, a Google-owned open-source tool, was found to have a critical command injection vulnerability in a custom action, enabling attackers to gain full repository access and exfiltrate secrets 19:17-21:47.
This attack demonstrates how insecure inputs and dependency chains can lead to widespread compromise, even in well-maintained projects. Organizations must enforce input validation, audit third-party actions, and follow the principle of least privilege in CI/CD workflows.
Sources:
- 2:59 Overview of GitHub Actions vulnerabilities and attack surface
- 10:15-11:19 Demonstration of command injection via user-controlled inputs
- 14:55-15:31 Explanation of custom action dependency risks
- 19:17-21:47 Discovery and exploitation of Bazel’s command injection vulnerability
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
[Applause] yeah hear me thank you guys for joining us today it's the last day of Defcon appreciate that and thank you for joining to our talk your cicd pipeline is vulnerable but it's not your fault so without further Ado let's move on in a minute we're not moving on try it again yeah so my name is alad I'm a security researcher at pyod with seven years of experience I'm mainly focusing on web application security and supply chain security and I'm love I'm love I can random stuff basically everything with an IP and I'm from pyod hi my name is Zin I hope the presentation will work because I saw H um so I have also seven years of experience in cyber security in my background I used to research car Bros and networking but currently I focus on supply chain Security on the same research team wi…