logo

Abuse of Repository Webhooks to Access Hundreds of Internal CI Systems

Conference:  RSA Conference 2023

2023-04-24

Authors:   Omer Gil, Asaf Greenholts


Abstract

Many organizations opt for a CI/CD architecture that combines SaaS-based source control management systems with a self-managed CI solution not exposed to the public Internet. In this talk presenters will discuss a novel attack vector, allowing anyone on the Internet to abuse repository webhooks to do much more than trigger pipelines, and show how they accessed hundreds of internal CI systems in scale.

Materials:

Tags:

Post a comment

Related work