commit-hash-collision

1 article
sort: new top best
clear filter
0 8/10
vulnerability

A researcher discovered that GitHub Actions' use of abbreviated 7-character commit hashes in workflow configs could be exploited to cause global DoS by generating intentional commit hash collisions, which would cause tarball downloads to fail with 404 errors for anyone referencing the ambiguous shorthash. The vulnerability was fixed by updating the config wizard to generate full 40-character commit hashes instead.

GitHub Actions actions/docker 76ff57a 76ff57aa21370794040cd0caafd84d8a7aa0927c
blog.teddykatz.com · devanshbatham/Awesome-Bugbounty-Writeups · 4 hours ago · details