Lemmy.one
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
Tiff@reddthat.com to TechSploits@reddthat.comEnglish · 20 days ago

How We Exploited CodeRabbit: From a Simple PR to RCE and Write Access on 1M Repositories

research.kudelskisecurity.com

external-link
message-square
0
fedilink
  • cross-posted to:
  • Technology@programming.dev
  • cybersec@fed.dyne.org
  • security@lemmy.ml
  • hackernews@lemmy.bestiver.se
3
external-link

How We Exploited CodeRabbit: From a Simple PR to RCE and Write Access on 1M Repositories

research.kudelskisecurity.com

Tiff@reddthat.com to TechSploits@reddthat.comEnglish · 20 days ago
message-square
0
fedilink
  • cross-posted to:
  • Technology@programming.dev
  • cybersec@fed.dyne.org
  • security@lemmy.ml
  • hackernews@lemmy.bestiver.se
In this blog post, we explain how we got remote code execution (RCE) on CodeRabbit’s production servers, leaked their API tokens and secrets, how we could have accessed their PostgreSQL datab…
alert-triangle
You must log in or # to comment.

TechSploits@reddthat.com

techsploits@reddthat.com

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !techsploits@reddthat.com

All things relating to breaking tech, tech breaking, OSS, or hacking together software to perform something completely out of the ordinary, on purpose or by accident.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 4 users / day
  • 4 users / week
  • 57 users / month
  • 158 users / 6 months
  • 7 local subscribers
  • 484 subscribers
  • 126 Posts
  • 87 Comments
  • Modlog
  • mods:
  • Red@reddthat.com
  • BE: 0.19.7
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org