You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hello,
I am Sébastien Graveline, Security Researcher at BoostSecurity.io.
We have been tasked by Red Hat Product Security to scan and triage Supply Chain vulnerabilities in Red Hat's open-source software (OSS) repositories.
Hello,
I am Sébastien Graveline, Security Researcher at BoostSecurity.io.
We have been tasked by Red Hat Product Security to scan and triage Supply Chain vulnerabilities in Red Hat's open-source software (OSS) repositories.
GHSA-634r-6g9q-9v57
The fix for GHSA-634r-6g9q-9v57 is accurate, but since the workflow is using pull_request_target, it should be fixed on every branches, since it can be exploited just the same on a non-default branch such as https://github.com/redhat-developer/rhdh/blob/release-1.7/.github/workflows/pr-build-image.yaml.