github.com/tektoncd/pipeline is vulnerable to Insertion of Sensitive Information Into Sent Data
77
High Risk
An improper access control issue in Tekton Pipelines git resolver API mode allowed users with permission to create TaskRun or PipelineRun resources to supply a user-controlled serverURL while omitting the token parameter, causing the resolver to reuse the system-configured Git API token for requests to an attacker-controlled server. This enabled exfiltration of shared credentials such as GitHub PATs or GitLab tokens, potentially exposing private repositories, source code, CI/CD configuration, and other sensitive data.
You are affected if you are using a version that falls within the vulnerable range.
github.com/tektoncd/pipeline is vulnerable to Insertion of Sensitive Information Into Sent Data in versions 1.10.0 - 1.11.0, 1.7.0 - 1.9.2, 1.4.0 - 1.6.1, 1.2.28 - 1.3.3 and 1.0.0 - 1.0.1.
Upgrade the github.com/tektoncd/pipeline library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant