### Impact The CodeQL runner tool
Medium4.4CVE-2021-32638 · Published May 25, 2021
### Impact The CodeQL runner tool, provided to run CodeQL-based code scanning on non-GitHub CI/CD systems, requires a GitHub access token to connect to a GitHub repository. The runner and its documentation previously suggested passing the GitHub token as a command-line parameter to the process instead of reading it from a file, standard input, or an environment variable. For example: ``` /path/to-runner/codeql-runner-linux <command> <args> --github-auth TOKEN ``` This approach made the token visible to other processes on the same machine, for example in the output of the `ps` command. If the CI system publicly exposes the output of `ps`, for example by logging the output, then the GitHub access token can be exposed beyond the scope intended. Users of the CodeQL runner on 3rd-party systems, who are passing a GitHub token via the `--github-auth` flag, are affected. This applies to both GitHub.com and GitHub Enterprise users. Users of the CodeQL Action on GitHub Actions are not affected. ### Mitigation / new behavior The `--github-auth` flag is now considered insecure and deprecated. The undocumented `--external-repository-token` flag has been removed. To securely provide a Git...
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| CodeQL runner Product | < codeql-bundle-20210304 | codeql-bundle-20210304 |
Details and references
### Impact The CodeQL runner tool, provided to run CodeQL-based code scanning on non-GitHub CI/CD systems, requires a GitHub access token to connect to a GitHub repository. The runner and its documentation previously suggested passing the GitHub token as a command-line parameter to the process instead of reading it from a file, standard input, or an environment variable. For example: ``` /path/to-runner/codeql-runner-linux <command> <args> --github-auth TOKEN ``` This approach made the token visible to other processes on the same machine, for example in the output of the `ps` command. If the CI system publicly exposes the output of `ps`, for example by logging the output, then the GitHub access token can be exposed beyond the scope intended. Users of the CodeQL runner on 3rd-party systems, who are passing a GitHub token via the `--github-auth` flag, are affected. This applies to both GitHub.com and GitHub Enterprise users. Users of the CodeQL Action on GitHub Actions are not affected. ### Mitigation / new behavior The `--github-auth` flag is now considered insecure and deprecated. The undocumented `--external-repository-token` flag has been removed. To securely provide a GitHub access token to the CodeQL runner, users should **do one of the following instead**: - Use the `--github-auth-stdin` flag and pass the token on the command line via standard input: ``` echo "$TOKEN" | /path/to-runner/codeql-runner-linux <command> <args> --github-auth-stdin ``` - Set the `GITHUB_TOKEN` environment variable to contain the token, then call the command without passing in the token: ``` # set GITHUB_TOKEN to the token, using your CI system's secret storage mechanism /path/to-runner/codeql-runner-linux <command> <args> ``` The old flag remains present for backwards compatibility with existing workflows. If the user tries to specify an access token using the `--github-auth` flag, there is a deprecation warning printed to the terminal that directs the user to one of the above options. For more information, see the GitHub documentation pages linked below. ### Patches All CodeQL runner releases from https://github.com/github/codeql-action/releases/tag/codeql-bundle-20210304 onwards contain the patches: - https://github.com/github/codeql-action/commit/88714e3a60e72ec53caa0e6a203652ee1f3fb1db deprecates the `--github-auth` flag - https://github.com/github/codeql-action/commit/58defc0652e935f6f2ffc70a82828b98d75476fb removes the `--external-repository-token` flag ### Workarounds - We recommend updating to a recent version of the CodeQL runner, storing a token in your CI system's secret storage mechanism, and passing the token to the CodeQL runner using `--github-auth-stdin` or the `GITHUB_TOKEN` environment variable. - If still using the old flag, ensure that process output, such as from `ps`, is not persisted in CI logs. ### References - GitHub documentation - https://docs.github.com/en/code-security/secure-coding/using-codeql-code-scanning-with-your-existing-ci-system/running-codeql-runner-in-your-ci-system - https://docs.github.com/en/code-security/secure-coding/using-codeql-code-scanning-with-your-existing-ci-system/configuring-codeql-runner-in-your-ci-system#init - https://cwe.mitre.org/data/definitions/214.html - https://www.netmeister.org/blog/passing-passwords.html ### For more information If you have any questions or comments about this advisory: * [Open an issue](https://github.com/github/codeql-action/issues/new) * Contact us as described in the [security policy](https://github.com/github/codeql-action/security/policy) ### Credit Thanks to `@jlleitschuh` for reporting this vulnerability through our Bug Bounty program.
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-214
More GitHub advisories
All GitHub| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jan 242025 | GitHub PAT written to debug artifacts | High | 3.28.3+1 more |
| Jul 252024 | Arbitrary File Overwrite in CodeQL versions less than 2.18.1 | High | 2.18.1 |
| Feb 222024 | Limited data exfiltration in CodeQL CLI | Low2.7 | 2.16.3 |
| Jan 222020 | Limited header injection when using dynamic overrides with user input | Medium | ~3.9 |
| Jan 222020 | Directive injection when using dynamic overrides with user input | Medium | ~3.8 |
| Nov 222019 | Arbitrary code execution when opening a malicious workspace | High | 1.0.1 |