Hunt Cicd

Hunt CI/CD pipeline vulnerabilities — GitHub Actions workflow injection (pull_request_target Pwnrequest + ${{ }}-into-shell), self-hosted runner poisoning, OIDC trust-policy abuse, Jenkins script-console RCE and CVE-2024-23897 file read, GitLab CI runner-token registration, Terraform state file leakage, artifact/log secret leakage, pipeline env-var disclosure. Use when target has a public GitHub/GitLab org, exposed CI dashboards (Jenkins/TeamCity/Drone/Argo), or build artifacts/images are reachable.

uphiago 8ef04ab 19.0 KB Updated

File contents

uphiago/recon-skills/tree/main/redteam/hunt-cicd commit 8ef04abc2e

Frequently asked questions

npx skillmds@latest add uphiago/hunt-cicd