Sorcery Blog · Aug 3, 2024
CFOR Exploit - Recovering Deleted and Private Github Commits
0Sign in to vote or save
This page cannot be shown here. You can still read it on the original site — the toolbar below keeps your place in the directory.
CFOR stands for Cross Fork Object Reference. It’s an information disclosure vulnerability where deleted commits or commits from private forks can be exposed if you know the commit hash, it’s similar to an IDOR. The details about the flaw can be read in this blog post by TruffleSecurity who discovered the issue. After reading that blog post I started writing an exploit script for it to…
Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.