Settings

Theme

CI/CD supply chain attack on Azure Karpenter Provider open-source project

stepsecurity.io

3 points by varunsharma07 a year ago · 2 comments

Reader

varunsharma07OP a year ago

An independent security researcher, on August 31st, 2024, demonstrated a successful supply chain attack on Azure Karpenter Provider, an open-source project maintained by Microsoft. A vulnerable GitHub Actions workflow led to this attack. The researcher successfully exploited the vulnerability and gained access to the workflow's GITHUB_TOKEN, which had "id-token: write" permission to the repository.

blinded a year ago

Karpenter is legit 10/10. When deployed it saved us 15~% of our cpu spend.

Keyboard Shortcuts

j
Next item
k
Previous item
o / Enter
Open selected item
?
Show this help
Esc
Close modal / clear selection