Junglewise Threat Intelligence

CVE-2020-11021: GitHub Actions http-client authorization header leak on redirect

CVE-2020-11021 · Severity: low · CVSS 3.1 · Published 2020-04-29

Vendors: GitHub, npm.

Executive brief

GitHub Actions' http-client library fails to remove authentication credentials when an HTTP request is redirected to a different hostname. An attacker who controls a server that receives a redirected request could intercept the authorization token, potentially gaining access to GitHub resources and workflows. This affects automated CI/CD pipelines that make outbound HTTP requests using this library.

Technical details

The vulnerability is an information disclosure (CWE-200) in the HTTP redirect handling logic. When the http-client library receives a 302 HTTP redirect response and the redirect target is on a different hostname, the library does not strip the Authorization header before following the redirect. An attacker who controls the destination hostname can capture the Authorization header (including the scoped GITHUB_TOKEN) sent by the Actions runner. This requires the Actions workflow to make an HTTP request that redirects to an attacker-controlled domain. The vulnerability is fixed in version 1.0.8 by stripping the Authorization header when the hostname differs between the original request and redirect target.

Affected products

  • GitHub Actions http-client < 1.0.8

Timeline

  • 2020-04-29: disclosed
  • 2020-04-29: patched: Fix released in version 1.0.8

References