Apache Doris Zero-Click CI/CD Attacks
Apache Doris was vulnerable to zero-click CI/CD attacks that allowed code execution and credential theft through pull request comments.
Apache Doris was vulnerable to zero-click CI/CD attacks that allowed code execution and credential theft through pull request comments.
Cybersecurity researchers at Novee Security have identified a critical exploitable pattern in CI/CD workflows, codenamed Cordyceps, that allows unauthenticated attackers to hijack…