
Snowflake GitHub Actions Injection Flaw Exposes Internal Jira Credentials
An autonomous AI security agent, Wiz Red Agent, uncovered a critical GitHub Actions injection vulnerability in Snowflake’s public snowflake-connector-net repository. The flaw enabled an unauthenticated GitHub user to execute arbitrary commands on a GitHub Actions runner and exfiltrate credentials for Snowflake’s internal Jira environment. The discovery demonstrates how a small CI/CD coding error can lead […]
The post Snowflake GitHub Actions Injection Flaw Exposes Internal Jira Credentials appeared first on Cyber Security News.