Unauthorized access to Codespace secrets in GitHub
Published Mon, Mar 6th, 2023
Platforms
Summary
A vulnerability in GitHub's Repository Security Advisory feature allowed unauthorized users to access plaintext Codespace secrets of any organization, including GitHub itself. The issue stemmed from the new beta feature that allows external users to report vulnerabilities to public repositories, inadvertently granting access to sensitive organization-level secrets.
Organizations should review their GitHub Codespace secrets and ensure that no unauthorized access has occurred. Additionally, they should monitor for any suspicious activity related to their GitHub repositories and Codespace environments.