CVE-2025-62794
Beschrijving NL
GitHub Workflow Updater is een VS-code-extensie die GitHub-acties automatisch vastlegt op specifieke commits voor verbeterde beveiliging. Vóór 0.0.7 zou elk verstrekt Github-token in platte tekst worden opgeslagen in de editorconfiguratie als json op schijf, in plaats van via de veiligere "securestorage" -api. Een aanvaller met alleen-lezen toegang tot uw thuismap had dit token kunnen lezen en het kunnen gebruiken om acties met dat token uit te voeren. Update naar 0.0.7.
Origineel (Engels) tonen
GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced security. Before 0.0.7, any provided Github token would be stored in plaintext in the editor configuration as json on disk, rather than through the more secure "securestorage" api. An attacker with read only access to your home directory could have read this token and used it to perform actions with that token. Update to 0.0.7.