Skip to content

Wiz: Potential Leak via AWS command #2841

Description

@pooleycodes

https://app.wiz.io/issues?filters=%7B%22status%22%3A%7B%22equals%22%3A%5B%22OPEN%22%2C%22IN_PROGRESS%22%5D%7D%7D#%7E%28issue%7E%2744623653-4dbb-4a2d-aac3-46163d8f629c%29

Do we need to use https://github.com/digital-land/digital-land-lambda/blob/969a30452474e0ca5e40834e00eac5a78e52553f/.github/workflows/deploy.yml#L104 line?

This publicly exposed code repository contains a workflow that potentially leaks secrets in environment variables in the workflow logs.

Workflow logs from publicly exposed repositories are available for download externally depending on the retention policy. This is a potential path for privilege escalation and an abuse of leaked secrets.

Also the same goes for https://github.com/digital-land/mwaa-authx-lambda/blob/e2473455f30ed7bba5ba3c05de98ece5c8753a56/.github/workflows/publish.yml#L85, does that command need to be used as risk here (different command to above)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    Status
    Sprint Backlog ⏭️

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions