CVE-2021-32638 describes an information exposure vulnerability in GitHub's CodeQL action, affecting users running CodeQL on non-GitHub CI/CD systems. Previously, passing a GitHub access token via the --github-auth flag made it visible to other processes, potentially exposing it in system logs if publicly exposed. This could lead to unauthorized access to GitHub repositories. The vulnerability has a CVSS score of 4.4 (Medium), indicating a local attack vector with low attack complexity, requiring high privileges to exploit. The primary impact is high confidentiality loss, as the token could be compromised. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage are minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20210304CPE matchmatch criteria | cpe:2.3:a:github:codeql_action:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.