CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4555

As cited

Copy frozen at (site build).

vulnerabilities

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Wiz researchers disclosed a GitHub Actions workflow injection vulnerability in Snowflake's snowflake-connector-net repository that could allow attackers to execute commands through a crafted GitHub issue. The flaw affects the jira_issue.yml workflow file and exposes internal Jira credentials during workflow execution.

Why it matters: Developers using Snowflake connectors should review their GitHub Actions configurations and connected credentials for similar patterns, as attackers could inject malicious commands to compromise build environments and steal secrets.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Wiz researchers disclosed a GitHub Actions workflow injection vulnerability in Snowflake's snowflake-connector-net repository that could allow attackers to execute commands through a crafted GitHub issue. The flaw affects the jira_issue.yml workflow file and exposes internal Jira credentials during workflow execution.

Why it matters: Developers using Snowflake connectors should review their GitHub Actions configurations and connected credentials for similar patterns, as attackers could inject malicious commands to compromise build environments and steal secrets.

VendorsAtlassianGitHubSnowflake
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary