coder / coder/envbuilder

vulnerability in envbuilder project

未关闭
#484 0 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
主要语言
Go
星标
300
派生
64
平均合并
20 分钟
30 天内合并 PR
1

描述

While working on envbuilder project, I discovered a vulnerability [(CVE-2025-66411](https://vulert.com/vuln-db/CVE-2025-66411)) in the github.com/coder/coder/v2 package. The issue occurs because the Workspace Agent logs sensitive environment variables in plaintext without sanitization. Updating to the patched version and disabling agent logs temporarily mitigates the risk.

[CVE Link](https://vulert.com/vuln-db/CVE-2025-66411)
[CVE Report](https://vulert.com/vuln-scan/list/ba54e292-6b19-462d-b02d-77839d9a04f9)

贡献指南

这个仓库没有索引到贡献指南

调研方向

未确定任何文件、测试或入口点。首先跟踪 envbuilder 对 github.com/coder/coder/v2 的使用情况以及 Workspace Agent 的日志记录路径;确认依赖项更新和日志记录行为能够解决报告的环境变量明文暴露问题。

由索引模型根据 Issue 内容生成。

评估

技术栈
go
领域
security
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
需要澄清
新手友好度
25/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。