漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Duck Site: Untrusted pull request code can trigger privileged production deployment
Vulnerability Description
In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. The build workflow runs on pull requests, while the deploy workflow runs with package-write permissions and deployment secrets. If an attacker can make a pull request build satisfy the deploy workflow’s main branch condition, the deploy job checks out the triggering workflow commit, builds it into a Docker image, pushes it as latest, and triggers Dokploy deployment. This can allow attacker-controlled pull request code to become the deployed production site image without being merged. This issue has been patched in version 1.0.1.
CVSS Information
N/A
Vulnerability Type
从非可信控制范围包含功能例程
Vulnerability Title
Duck Site 安全漏洞
Vulnerability Description
Duck Site是Duck Organization开源的一个网站内容管理工具。 Duck Site 1.0.1之前版本存在安全漏洞,该漏洞源于部署工作流条件检查不当,可能导致攻击者控制的拉取请求代码成为已部署的生产站点镜像。
CVSS Information
N/A
Vulnerability Type
N/A