* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Monday, August 18, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Terence Stamp: from arthouse icon to blockbuster villain – yahoo.com

    Terence Stamp: From Arthouse Legend to Hollywood’s Ultimate Villain

    Community & Entertainment redefined: The summer fun continues with Villagio Hospitality! – WJLA

    Summer Fun Redefined: Create Unforgettable Moments with Villagio Hospitality!

    Iconic ‘M*A*S*H’ Actor, 86, Has Fans Swooning Over Resurfaced Images: ‘My Crush Since ’75’ – yahoo.com

    Iconic ‘M*A*S*H’ Actor, 86, Has Fans Swooning Over Resurfaced Images: ‘My Crush Since ’75’ – yahoo.com

    ‘The Rainmaker’ Premiere: Milo Callaghan Breaks Down Rudy Baylor’s ‘Misguided Valor’ – The Laconia Daily Sun

    Inside ‘The Rainmaker’ Premiere: Milo Callaghan Uncovers the Real Story Behind Rudy Baylor’s Misguided Valor

    Suicide Squad Member Gets New Origin in Absolute Flash – yahoo.com

    Suicide Squad Member Unveiled with Exciting New Origin in Absolute Flash

    I’ll miss the chaos of ‘And Just like That…’ (and Che Diaz too) – yahoo.com

    Why I’ll Truly Miss the Wild Ride of ‘And Just Like That…’ (and Che Diaz!)

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Empyrean Technology’s revenue climbs, but profit plunges 92% in EDA spending squeeze – digitimes

    Empyrean Technology’s Revenue Skyrockets as Profits Plunge 92% Amid EDA Spending Crunch

    5G-A technology provides strong support for China’s football sensation Suchao – Global Times

    How 5G-A Technology is Revolutionizing China’s Football Star Suchao

    AI’s backyard: A map of the 21st-century gold rush – EL PAÍS English

    The AI Frontier: Exploring the Thrilling Gold Rush of the 21st Century

    Youxin Technology Ltd Faces Nasdaq Deficiency Notices Over Listing Compliance Issues

    Vermont famers say new technology is changing the state’s agriculture industry – News Channel 3-12

    Vermont Farmers Embrace New Technology Transforming the State’s Agriculture Industry

    Verb Technology Reports Revenue Growth Amidst Strategic Expansions – TipRanks

    Verb Technology Soars with Impressive Revenue Growth Driven by Strategic Expansions

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Terence Stamp: from arthouse icon to blockbuster villain – yahoo.com

    Terence Stamp: From Arthouse Legend to Hollywood’s Ultimate Villain

    Community & Entertainment redefined: The summer fun continues with Villagio Hospitality! – WJLA

    Summer Fun Redefined: Create Unforgettable Moments with Villagio Hospitality!

    Iconic ‘M*A*S*H’ Actor, 86, Has Fans Swooning Over Resurfaced Images: ‘My Crush Since ’75’ – yahoo.com

    Iconic ‘M*A*S*H’ Actor, 86, Has Fans Swooning Over Resurfaced Images: ‘My Crush Since ’75’ – yahoo.com

    ‘The Rainmaker’ Premiere: Milo Callaghan Breaks Down Rudy Baylor’s ‘Misguided Valor’ – The Laconia Daily Sun

    Inside ‘The Rainmaker’ Premiere: Milo Callaghan Uncovers the Real Story Behind Rudy Baylor’s Misguided Valor

    Suicide Squad Member Gets New Origin in Absolute Flash – yahoo.com

    Suicide Squad Member Unveiled with Exciting New Origin in Absolute Flash

    I’ll miss the chaos of ‘And Just like That…’ (and Che Diaz too) – yahoo.com

    Why I’ll Truly Miss the Wild Ride of ‘And Just Like That…’ (and Che Diaz!)

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Empyrean Technology’s revenue climbs, but profit plunges 92% in EDA spending squeeze – digitimes

    Empyrean Technology’s Revenue Skyrockets as Profits Plunge 92% Amid EDA Spending Crunch

    5G-A technology provides strong support for China’s football sensation Suchao – Global Times

    How 5G-A Technology is Revolutionizing China’s Football Star Suchao

    AI’s backyard: A map of the 21st-century gold rush – EL PAÍS English

    The AI Frontier: Exploring the Thrilling Gold Rush of the 21st Century

    Youxin Technology Ltd Faces Nasdaq Deficiency Notices Over Listing Compliance Issues

    Vermont famers say new technology is changing the state’s agriculture industry – News Channel 3-12

    Vermont Farmers Embrace New Technology Transforming the State’s Agriculture Industry

    Verb Technology Reports Revenue Growth Amidst Strategic Expansions – TipRanks

    Verb Technology Soars with Impressive Revenue Growth Driven by Strategic Expansions

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

GitHub fixes race condition that could have led to ‘repojacking’

September 18, 2023
in Technology
GitHub fixes race condition that could have led to ‘repojacking’
Share on FacebookShare on Twitter

Jürgen Fälchle – stock.adobe.c

A subtle flaw in how GitHub handled repository creation and user renaming could have had serious consequences for the open source community, but has now been fixed. Learn more about how it worked

Alex Scroxton

By

Alex Scroxton,
Security Editor

Published: 13 Sep 2023 16:00

GitHub has fixed a race condition vulnerability in its repository creation and user renaming operations that could have enabled threat actors to perform what is known as a repojacking attack.

Discovered and disclosed by researchers from Checkmarx, had the flaw been exploited, it could have been used to take control of code repositories and hijack them to distribute malicious code. It would also have had bad implications for the reputations of those who fell victim to it.

“Repojacking is a technique where an attacker takes control of a GitHub repository by exploiting a logical flaw that renders renamed users vulnerable,” wrote Elad Rapoport of Checkmarx.

“The attacker hijacks a legitimate, often popular, namespace on GitHub. A namespace is the combination of the username and repo name, for example: example-user/example-repo.”

Namespaces on GitHub become vulnerable to repojacking when the original username is changed using the “user rename” feature. When a GitHub user renames themselves, GitHub does not set up redirects for their old profile page or Pages sites, but does create redirects for their repositories. Users are made aware of this via a pop-up during the process.

Unfortunately, in doing so, the old username also becomes available for anybody else to claim, so once the user has been successfully renamed, a malicious actor can claim their old username, open a repo under the matching repo name, and hijack the namespace.

Other flaws in this process have previously been identified and fixed, and GitHub did have protection measures available – notably retiring popular repositories (those with more than 100 clones at the time of renaming) so that the username couldn’t be taken.

However, Rapoport found he was able to bypass these fixes by taking advantage of a race condition between the creation of a repository and the renaming of a username, by almost simultaneously doing both – using an API request for repository creation and a renamed request interception for the username change.

“Successful exploitation enables the takeover of popular code packages in several package managers, including ‘Packagist,’ ‘Go,’ ‘Swift’ and more,” he said. “We have identified over 4,000 packages in those package managers using renamed usernames and are at risk of being vulnerable to this technique in case a new bypass is found. Of these packages at risk, hundreds of them have garnered over 1,000 stars on GitHub.

“In addition, exploiting this bypass can also result in a takeover of popular GitHub actions, which are also consumed by specifying a GitHub namespace. Poisoning a popular GitHub action could lead to major supply chain attacks with significant repercussions.”

Although this repojacking issue has been fixed, it is the fourth one found in the past couple of years – three in 2022 alone – and Rapoport said it spoke to persistent risks associated with the popular repository namespace retirement mechanism.

“Many GitHub users, including users that control popular repositories and packages, choose to use the ‘user rename’ feature GitHub offers,” he said. “For that reason, the attempt to bypass the ‘popular repository namespace retirement’ remains an attractive attack point for supply chain attackers with the potential to cause substantial damages.”

In spite of the fix, Checkmarx is recommending that users avoid using retired namespaces to minimise their attack surface, and make sure there are no code dependencies that may leave a GitHub repository vulnerable. It offers its own open source tool, Chainjacking, which can assist with this.

Read more on Web application security


Create a GitHub Personal Access Token example

CameronMcKenzie

By: Cameron McKenzie


Git commit config and credential confusion causes consternation for customers

CameronMcKenzie

By: Cameron McKenzie


Follow this Harness IO tutorial to get started with CI/CD

MichaelLevan

By: Michael Levan


Quick GitHub ‘Permission denied (publickey)’ SSH error fix

CameronMcKenzie

By: Cameron McKenzie

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366552015/GitHub-fixes-race-condition-that-could-have-led-to-repojacking

Tags: fixesGitHubtechnology
Previous Post

BianLian ransomware gang holds Save the Children hostage

Next Post

GCHQ breached privacy rights of IT professional and security researcher, human rights court rules

Can We Prevent Aging? Eric Topol on Genes, Lifestyle, and AI in Healthcare – Skeptic

Can We Prevent Aging? Eric Topol on Genes, Lifestyle, and AI in Healthcare – Skeptic

August 18, 2025
Empyrean Technology’s revenue climbs, but profit plunges 92% in EDA spending squeeze – digitimes

Empyrean Technology’s Revenue Skyrockets as Profits Plunge 92% Amid EDA Spending Crunch

August 18, 2025
William Edwin Kornowski – thealpenanews.com

William Edwin Kornowski – thealpenanews.com

August 18, 2025
Where can bluegrass go next? Molly Tuttle has an idea : World Cafe Words and Music Podcast – NPR

Molly Tuttle Reveals Her Exciting Vision for the Future of Bluegrass

August 18, 2025
‘Luck running out’ for Swiss economy as growth slows ahead of US tariff hit – Financial Times

Swiss Economy Faces Slowdown and Challenges Ahead of US Tariffs

August 18, 2025
Terence Stamp: from arthouse icon to blockbuster villain – yahoo.com

Terence Stamp: From Arthouse Legend to Hollywood’s Ultimate Villain

August 18, 2025
How social media and reality TV influence Teens’ beauty standards and mental health – Planet Detroit

How Social Media and Reality TV Influence Teens’ Beauty Ideals and Mental Well-Being

August 18, 2025
Putin praises Trump for ‘sincere’ efforts to end war – CNN

Putin Praises Trump’s Sincere Push to End the War

August 18, 2025
Green High-Yield and High-Efficiency Technology: A New Path Balancing Yield and Ecology | Newswise – Newswise

Revolutionizing Sustainability: High-Yield Green Technology for Maximum Efficiency and Ecological Harmony

August 17, 2025
MassDOT & Museum Of Science Propose Riverwalk To Connect Boston & Cambridge – WBZ NewsRadio 1030

MassDOT & Museum Of Science Propose Riverwalk To Connect Boston & Cambridge – WBZ NewsRadio 1030

August 17, 2025

Categories

Archives

August 2025
MTWTFSS
 123
45678910
11121314151617
18192021222324
25262728293031
« Jul    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (776)
  • Economy (798)
  • Entertainment (21,676)
  • General (16,530)
  • Health (9,837)
  • Lifestyle (810)
  • News (22,149)
  • People (800)
  • Politics (806)
  • Science (16,011)
  • Sports (21,297)
  • Technology (15,779)
  • World (780)

Recent News

Can We Prevent Aging? Eric Topol on Genes, Lifestyle, and AI in Healthcare – Skeptic

Can We Prevent Aging? Eric Topol on Genes, Lifestyle, and AI in Healthcare – Skeptic

August 18, 2025
Empyrean Technology’s revenue climbs, but profit plunges 92% in EDA spending squeeze – digitimes

Empyrean Technology’s Revenue Skyrockets as Profits Plunge 92% Amid EDA Spending Crunch

August 18, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version