▲ 28 ▼ CVE: Possible Organization/Secret Compromise from dangerous CI implementation (www.cvedetails.com) submitted 4 months ago* by le_throosh@lemmy.dbzer0.com to c/jellyfin@lemmy.ml 6 comments fedilink hide all child comments Strange that there was no comms whatsover from the team about this
[+] renegadespork@lemmy.jelliefrontier.net 6 points 4 months ago (4 children) [deleted] permalink fedilink source hideshow 8 child comments replies: [–] Link@rentadrunk.org 8 points 4 months ago* Hasn’t it already been patched? https://github.com/jellyfin/jellyfin-ios/security/advisories/GHSA-7qhm-2m45-7fmh Patches CI workflows have been modified in all affected repositories, and secrets have been rotated. Furthermore, OPs post seems to link to the patch: https://github.com/jellyfin/jellyfin-ios/commit/109217e75f38394b2f6e46e25dfe5a721203d3c8 permalink fedilink source parent [–] slacktoid@lemmy.ml 4 points 4 months ago (1 child) This doesn't affect the code or jellyfin. Its a problem with how github does CI that needs to be fixed. permalink fedilink source parent hideshow 2 child comments replies: [+] renegadespork@lemmy.jelliefrontier.net 1 point 4 months ago [deleted] permalink fedilink source parent [–] noodle@aus.social 1 point 4 months ago (1 child) @renegadespork @le_throosh "Note: This is not a code vulnerability, but a vulnerability in the GitHub Actions workflows. No new version is required for this GHSA and end users do not need to take any actions." permalink fedilink source parent hideshow 2 child comments replies: [+] renegadespork@lemmy.jelliefrontier.net 1 point 4 months ago [deleted] permalink fedilink source parent [–] le_throosh@lemmy.dbzer0.com [S] 1 point 4 months ago I think its our local copies that might have issues if anything. If there is a threat at all, it would affect releases prior to the cve release not since then. Or yeah, if a possible attacker had gained access they may still have it, but its unlikely that would not have been caught. permalink fedilink source parent
[–] Link@rentadrunk.org 8 points 4 months ago* Hasn’t it already been patched? https://github.com/jellyfin/jellyfin-ios/security/advisories/GHSA-7qhm-2m45-7fmh Patches CI workflows have been modified in all affected repositories, and secrets have been rotated. Furthermore, OPs post seems to link to the patch: https://github.com/jellyfin/jellyfin-ios/commit/109217e75f38394b2f6e46e25dfe5a721203d3c8 permalink fedilink source parent
[–] slacktoid@lemmy.ml 4 points 4 months ago (1 child) This doesn't affect the code or jellyfin. Its a problem with how github does CI that needs to be fixed. permalink fedilink source parent hideshow 2 child comments replies: [+] renegadespork@lemmy.jelliefrontier.net 1 point 4 months ago [deleted] permalink fedilink source parent
[+] renegadespork@lemmy.jelliefrontier.net 1 point 4 months ago [deleted] permalink fedilink source parent
[–] noodle@aus.social 1 point 4 months ago (1 child) @renegadespork @le_throosh "Note: This is not a code vulnerability, but a vulnerability in the GitHub Actions workflows. No new version is required for this GHSA and end users do not need to take any actions." permalink fedilink source parent hideshow 2 child comments replies: [+] renegadespork@lemmy.jelliefrontier.net 1 point 4 months ago [deleted] permalink fedilink source parent
[+] renegadespork@lemmy.jelliefrontier.net 1 point 4 months ago [deleted] permalink fedilink source parent
[–] le_throosh@lemmy.dbzer0.com [S] 1 point 4 months ago I think its our local copies that might have issues if anything. If there is a threat at all, it would affect releases prior to the cve release not since then. Or yeah, if a possible attacker had gained access they may still have it, but its unlikely that would not have been caught. permalink fedilink source parent