github.com/buildkite/agent/v3 is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere
10
Low Risk
Affected versions of this package are vulnerable to Information Exposure through the buildkite-agent oidc request-token command due to the lack of automatic redaction for OIDC tokens in build logs. Unlike the secret get command, which automatically masks sensitive values, the OIDC token command outputs the raw, sensitive token in plaintext. An attacker with access to build logs (e.g., through a compromised account or misconfigured log storage) could harvest these exposed tokens, which may then be used to impersonate the build identity and gain unauthorized access to dependent services and resources.
You are affected if you are using a version that falls within the vulnerable range.
github.com/buildkite/agent/v3 is vulnerable to Exposure of Sensitive System Information to an Unauthorized Control Sphere in versions 3.41.0 - 3.103.1.
Upgrade the github.com/buildkite/agent/v3 library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant