Skip to content

Grafana says stolen GitHub token allowed attackers to download its codebase

bleepingcomputer.com
14 pointsp_stuart821 comment
On HN

Comments

GH provides an IP allow list and corp proxy capability to enterprise users. Unless the attacker pwned the entire corp network which is worse than leaking a token, these types of issues can mitigated. Tokens are useless if they don't originate from a specific IP space or contain the proxy header, but you have to set them up.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.