Securing CI/CD Pipelines - Exploring Vulnerabilities In Workflows

No ratings

Presented at NULLCON GOA 2023 by

Millions of software projects benefit from CI/CD platforms such as GitHub Actions, which streamline build and deployment tasks significantly. While these platforms have greatly improved the software build process for developers, they have also brought about new challenges. One of these is the increased risk to the software supply chain due to the introduction of additional dependencies and a higher degree of code complexity, both of which can potentially lead to security bugs. In this talk, we delve into the security characteristics of popular CI/CD platforms, building a comprehensive threat model for users. We briefly describe challenges in identifying vulnerabilities in CI/CD pipelines and introduce our taint tracking tool, specifically designed to identify code injection bugs in GitHub Workflows. We will conclude by examining a selection of real-world bugs, picked from over 23,000 bugs found by our tool.