Github wikis are editable by anyone #Githubwikistakeover

Disclosed: 2019-05-25 21:13:37 By ronb1996 To curl
Low
Vulnerability Details
Hey Curl, Github wiki on the following project, https://github.com/curl/curl/wiki can be edited by any logged in user in the system. This poses security and reputation risk for the company. As your policy i doesnot edited any of the wiki :-) Regards, @MSRC29 ## Impact As wikis listed above can be edited by any person on the internet, a malicious actor can accurately craft a message or a note which would lead a user to download a malicious component in a natural way. The user would surely trust the code (of course if he trusts the company itself), so he will extrapolate this trust to the wiki and consider it being safe enough to follow the instructions and downloading himself a malware.
Actions
View on HackerOne
Report Stats
  • Report ID: 545052
  • State: Closed
  • Substate: not-applicable
  • Upvotes: 6
Share this report