[actions] Add detection for workflow_dispatch TOCTOU
- Ngôn ngữ chính
- CodeQL
- Star
- 10.1k
- Fork
- 2.1k
- Merge trung bình
- 2 ngày 15 giờ
- Pull request đã merge (30 ngày)
- 141
Mô tả
**Description of the issue**
There is a newer variation of GitHub Actions TOCTOU vulnerabilities known as "Workflow dispatch TOCTOU" - I wrote about a real-world example in a recent bug report writeup:
https://adnanthekhan.com/posts/dependabot-core-toctou-writeup/
I think this is a good candidate for a `High` detection where a PR has the following characteristics:
* Runs on workflow dispatch / repository dispatch with the PR number as an input parameter. Does NOT require a commit SHA.
* Checks out code from that PR without some approval check.
* Runs code.
High because there is a lot of context required to understand if a maintainer would _actually_ ever run the workflow on a fork, and that is not possible to determine via static analysis alone.
I believe this would require some code changes in the library code - adding a concept of a non externally triggered workflow that is intended to act upon untrusted code. This could then fire the UntrustedCheckoutTOCTOU alert
Hướng dẫn đóng góp
Hướng nghiên cứu
Bắt đầu bằng cách xem xét các kịch bản workflow_dispatch và repository_dispatch của issue cùng với cảnh báo UntrustedCheckoutTOCTOU hiện có trong mã thư viện. Xác định cách biểu diễn các workflow hoạt động trên mã không đáng tin cậy mà không có bước kiểm tra phê duyệt, sau đó xác minh rằng các workflow khớp được phát hiện, còn các workflow yêu cầu một commit SHA thì không.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- github-actions
- Lĩnh vực
- ci-cd, security
- Loại issue
- Tính năng
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức độ hoạt động
- Đình trệ
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 25/100