Secrets for Every Fork — JavaScript Bug Hunt
Modelled on Travis CI's September 2021 security bulletin (CVE-2021-41077): for several days, the secure environment variables of public repositories —…
- Language: JavaScript
- Layer: Backend
- Difficulty: Easy
- Concepts: Security, Config
- Modelled on: Travis CI · CVE-2021-41077
- Visible tests: a push gets its secrets; a fork pull request gets no secrets
- Reward: 50 XP for a complete fix
Briefing
Modelled on Travis CI's September 2021 security bulletin (CVE-2021-41077): for several days, the secure environment variables of public repositories — signing keys, access tokens — were made available to builds of pull requests opened from forks. Anyone able to open a pull request could have a build read them.
env.js builds a job's environment. It is meant to hold secrets back from fork pull requests, but its check reads a field the build payload does not carry.
Fix buildEnv so secrets reach only pushes and pull requests opened from the same repository.
Bug report
BUG-FORKENV · Priority: Critical (secret exposure) · Reported by: security
buildEnv(build, settings) returns the job environment as an object:
- every settings.plain variable, in order
- then settings.secure variables ONLY when the build is trusted: build.event === "push", or build.event === "pull_request" with a headRepo equal to its baseRepo. A pull request whose headRepo differs (a fork) or is missing is untrusted.
- then TRAVIS_SECURE_ENV_VARS: "true" when secrets were added, else "false"
Observed: pull requests from forks receive DEPLOY_KEY and NPM_TOKEN.
Logs
[worker] job 88213 pull_request base=acme/site head=stranger/site
[worker] env: CI, DEPLOY_KEY, NPM_TOKEN, TRAVIS_SECURE_ENV_VARS=trueThe code as shipped
src/ci/env.js (editable)
// Builds the environment a CI job runs with.
exports.buildEnv = function (build, settings) {
var env = {};
Object.keys(settings.plain).forEach(function (k) { env[k] = settings.plain[k]; });
var trusted = build.event === "push" || !build.fork;
if (trusted) {
Object.keys(settings.secure).forEach(function (k) { env[k] = settings.secure[k]; });
}
env.TRAVIS_SECURE_ENV_VARS = trusted ? "true" : "false";
return env;
};
Read-only context: src/ci/BUILD.js.
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.