GeistHaus
log in · sign up

GitHub - RCE via git option injection (almost) - $20,000 Bounty

devcraft.io

It had been a while since I’d looked into GitHub, so I thought it would be good to spin up a fresh enterprise trial and see what I could find. The GHE code is obfuscated, but it’s just to discourage customers from messing around and if you do a bit of googling there are lots of scripts available to decode it leaving you with regular ruby files for a rails app.

0 pages link to this URL

No pages have linked to this URL yet.