Anyone can access deleted and private repository data on GitHub

__0x1__Wednesday, July 24, 2024

The linked article is about a security vulnerability in GitHub that allows anyone to access deleted and private repository data. The article explains how an attacker can use the GitHub API to retrieve deleted and private repository data, even if the repository has been made private or deleted. The vulnerability is caused by the way GitHub handles repository metadata and the inability to permanently delete repository data.

1963

372

trufflesecurity.com
Hazumi post image

Comments

372