Cybersecurity

We got admin access to Baseten's production GitHub in 25 minutes

A security vulnerability was found in Baseten's GitHub repository, allowing unauthorized access to administrative features in just 25 minutes. This was achieved through a GitHub Personal Access Token (PAT) takeover, where the attackers used a leaked PAT to gain admin access. The vulnerability was discovered by Strix AI, a security research team. Baseten is a low-code platform for building and deploying APIs. The security team was able to exploit the vulnerability using a GitHub PAT with a scope of 'repo' and 'admin:org' permissions. This allowed them to take control of the repository and make changes to the code. The vulnerability was patched by GitHub, and Baseten has since secured its repository. The security team noted that the vulnerability was a result of poor security practices, such as using a GitHub PAT with excessive permissions and not rotating the token regularly.

Read the full article at strix.ai →