RSSAmplifier

Sorcery Blog · Aug 3, 2024

CFOR Exploit - Recovering Deleted and Private Github Commits

0
Sign in to vote or save

This page cannot be shown here. You can still read it on the original site — the toolbar below keeps your place in the directory.

CFOR stands for Cross Fork Object Reference. It’s an information disclosure vulnerability where deleted commits or commits from private forks can be exposed if you know the commit hash, it’s similar to an IDOR. The details about the flaw can be read in this blog post by TruffleSecurity who discovered the issue. After reading that blog post I started writing an exploit script for it to…

Read on /posts/cfor_exploit/

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.