CVE: Possible Organization/Secret Compromise from dangerous CI implementation
CVE: Possible Organization/Secret Compromise from dangerous CI implementation
Hasn’t it already been patched? https://github.com/jellyfin/jellyfin-ios/security/advisories/GHSA-7qhm-2m45-7fmh
Patches
CI workflows have been modified in all affected repositories, and secrets have been rotated.
@renegadespork @le_throosh
"Note: This is not a code vulnerability, but a vulnerability in the GitHub Actions workflows. No new version is required for this GHSA and end users do not need to take any actions."
Edit: This is just for context to save others looking up the CVE. 'wait and see' makes sense, particularly when a major update is potentially in the near future.