8/9/2023 0 Comments Connect gitkraken to githubShortly after Axosoft's blog post, the security teams of Azure DevOps, GitHub, GitLab, and Atlassian's BitBucket have started revoking all SSH keys connected to accounts where the GitKraken app was used to synchronize source code. The attacker could then use these keys to access a user's account and steal proprietary source code.Īxosoft said that as soon as it learned of the issue, it replaced the keypair library inside the GitKraken app, released version 8.0.1, and notified the four platforms. In a blog post on Monday, Axosoft explained that versions 7.6.x, 7.7.x, and 8.0.0 of its GitKraken app used a library named " keypair" to generated SSH keys to allow developers to connect their GitKraken app to accounts on Azure DevOps, GitHub, GitLab, BitBucket, or other remote Git source code hosting servers.īut Axosoft said that older versions of this library generated RSA keys with low entropy, meaning that attackers could use the library, under certain conditions, to generate duplicate SSH keys. The mass revocations come at the request of Arizona-based software company Axosoft, which developed GitKraken and is the one who found the security flaw in its own software. Microsoft, GitHub, GitLab, and BitBucket -four of today's largest code hosting portals- have initiated mass revocations of SSH keys on Monday after the discovery of a vulnerability in a popular Git software client named GitKraken. Azure, GitHub, GitLab, BitBucket mass-revoke SSH keys following bug report
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |