github / github/vscode-github-actions

[SECURITY] Organization Variables Exposed in Plain Text to All Repository Users

オープン
#529 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
bug
主要言語
TypeScript
スター
660
フォーク
213
PR マージ指標
30日以内にマージされた PR はありません

説明

# [SECURITY] VS Code GitHub Actions extension exposes organization variables to non-admin users

## Summary

The GitHub Actions extension for VS Code exposes **organization-level Actions variable values (names + values)** to **non-admin users** via the “Settings → Variables → Organization Variables” view.

This is a **privilege escalation**:
- GitHub Web UI correctly blocks non-admins from viewing org variables
- `gh api repos/{owner}/{repo}/actions/organization-variables` correctly fails for non-admins
- Direct REST calls with a non-admin token also fail
- But the VS Code extension shows the **full values** to the same non-admin users

## Impact

**Severity: Critical – privilege escalation & credential disclosure**

For any repo where org variables are shared:

- Non-admin users with only read access to the repo can see:
- All shared org variable names
- Their **plain-text values** in the VS Code sidebar
- In our case this exposed (now rotated and moved to Secrets):
- `GITLAB_API_TOKEN` (full access to GitLab Package Registry)
- `GITLAB_API_READ_TOKEN`
- Multiple third‑party service passwords

## How to Reproduce

1. **Setup**

- In a GitHub organization:
- Create organization-level Actions variables with sensitive values
- Share them with a repository
- Add a **non-admin** user with read access to that repository

2. **As the non-admin user**

- Confirm that the org variables are **not** visible elsewhere:
- Web: Org Settings → Actions → Variables → **access denied**
- CLI:

```bash
gh api repos/{owner}/{repo}/actions/organization-variables
# => “Must have admin rights to Repository”
```

- In VS Code:
- Install `github.vscode-github-actions`
- Open the repo
- Open “GitHub Actions” view → “Settings” → “Variables” → “Organization Variables”

**Observed:** All organization variables and their values appear in plain text.

## Suspected Source

From the public repo:

- `src/treeViews/settings/orgVariablesNode.ts`:

```ts
variables = await this.gitHubRepoContext.client.paginate(
"GET /repos/{owner}/{repo}/actions/organization-variables",
{ owner: this.gitHubRepoContext.owner, repo: this.gitHubRepoContext.name, per_page: 100 }
);
return variables.map(v => new VariableNode(this.gitHubRepoContext, v, undefined, true));
```

- `src/treeViews/settings/variableNode.ts`:

```ts
export class VariableNode extends vscode.TreeItem {
constructor(/* ... */, public readonly variable: OrgVariable, /* ... */) {
super(variable.name);
this.description = variable.value; // shown directly in tree view
}
}
```

So the extension:

1. Calls the org variables API for the current repo
2. Wraps each result in a `VariableNode`
3. Sets `description = variable.value`, which is rendered in the tree view

The critical question: **why does this succeed for non-admin users when the same endpoint fails via `gh api` and curl?**

## Expected Behavior

- For non-admins:
- Either:
- Do not show “Organization Variables” at all, or
- Show only names, with values masked / hidden
- Enforce the same permission checks as:
- GitHub Web UI
- GitHub CLI
- Direct REST calls

## Mitigations (for other users)

Until fixed, organizations should:

- Rotate any secrets stored in organization variables that may have been exposed
- Move sensitive values to **GitHub Secrets**
- Avoid using this extension, or at least hide “Settings → Variables” from non-admins

## Request

Can the team:

1. Confirm the behavior with a non-admin test account?
2. Clarify which endpoint + auth flow the extension uses here?
3. Align the extension’s behavior with GitHub’s documented and enforced permission model for org variables?

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

Start with src/treeViews/settings/orgVariablesNode.ts and src/treeViews/settings/variableNode.ts, then reproduce the organization-variables request using a non-admin account. Compare the extension's endpoint and auth flow with the documented REST, CLI, and web behavior. Done means non-admin users cannot view organization variable values and the behavior matches the expected permission model.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
github-actions, typescript, vscode
領域
authorization, devtools, security
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
35/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。