More Haste, Less Speed: Cache Related Security Threats in Continuous Integration Services

被引:0
|
作者
Gu, Yacong [1 ,4 ]
Ying, Lingyun [2 ,4 ]
Chai, Huajun [2 ]
Pu, Yingyuan [2 ]
Duan, Haixin [1 ,4 ]
Gao, Xing [3 ]
机构
[1] Tsinghua Univ, Beijing, Peoples R China
[2] QI ANXIN Technol Res Inst, Singapore, Singapore
[3] Univ Delaware, Newark, DE USA
[4] Tsinghua Univ, QI ANXIN Grp JCNS, Beijing, Peoples R China
基金
美国国家科学基金会;
关键词
D O I
10.1109/SP54263.2024.00138
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Continuous Integration (CI) platforms have widely adopted caching to speed up CI task executions by storing and reusing dependent packages. Unfortunately, CI cache also exposes new attack surfaces when cache objects are shared across trust boundaries. In this paper, we systematically investigate potential security threats of CI cache features in seven mainstream CI platforms (CIPs). We find that existing CIPs have isolation issues in their cache sharing and inheritance strategies, potentially raising cache poisoning and data leakage problems. By exploiting these vulnerable mechanisms, we further uncover four attack vectors enabling attackers to stealthily inject malicious code into the cache or steal sensitive data. Even worse, many CIPs provide vulnerable official cache templates that will mistakenly store and expose sensitive data in the cache by default. To understand the potential impact of our disclosed threats, we develop an analysis tool and conduct a large-scale measurement on open-source repositories. Our measurement results show that many popular repositories are potentially affected by these attacks. We also identify 78 repositories that expose their high-value secrets in cache objects and are at risk of secret leakage. We have duly reported identified vulnerabilities to corresponding stakeholders and received positive responses.
引用
收藏
页码:1179 / 1197
页数:19
相关论文
共 50 条
  • [41] LESS HASTE, MORE SPEED? DO EUROPEAN ACCELERATED AUTHORISATIONS TRANSLATE INTO EARLY REIMBURSEMENT AND PATIENT ACCESS?
    Macaulay, R.
    Wang, G. D.
    Magimaidas, A.
    VALUE IN HEALTH, 2018, 21 : S164 - S164
  • [42] Inflammatory Bowel Disease and the SARS-CoV-2 Pandemic: More Speed, Less Haste Reply
    Norsa, Lorenzo
    D'Antiga, Lorenzo
    GASTROENTEROLOGY, 2021, 160 (01) : 474 - 475
  • [43] Alternative vector control methods to manage the Zika virus outbreak: more haste, less speed Reply
    Yakob, Laith
    Walker, Thomas
    LANCET GLOBAL HEALTH, 2016, 4 (06): : E365 - E366
  • [44] More haste less speed: A meta-analysis of thinking latencies during planning in people with psychosis
    Watson, Andrew J.
    Joyce, Eileen M.
    Fugard, Andrew J. B.
    Leeson, Verity C.
    Barnes, Thomas R. E.
    Huddy, Vyv
    PSYCHIATRY RESEARCH, 2017, 258 : 576 - 582
  • [45] More haste, less speed: pilot study suggests camera trap detection zone could be more important than trigger speed to maximise species detections
    Fancourt, Bronwyn A.
    Sweaney, Mark
    Fletcher, Don B.
    AUSTRALIAN MAMMALOGY, 2018, 40 (01): : 118 - 121
  • [46] More haste, less speed: leader bottom-line mentality and employee counter-productive social cyberloafing
    Zhou, Yue
    Chen, Peiyi
    Liu, Qingqing
    Wang, Tingxi
    JOURNAL OF MANAGERIAL PSYCHOLOGY, 2023, 38 (08) : 643 - 656
  • [47] Conservative initiation of antimicrobial treatment in ICU patients with suspected ICU-acquired infection: more haste less speed
    Hranjec, Tjasa
    Sawyer, Robert G.
    CURRENT OPINION IN CRITICAL CARE, 2013, 19 (05) : 461 - 464
  • [48] More haste, less speed? Relationship between response time and response accuracy in gamified online quizzes in an undergraduate engineering course
    Liang, Zilu
    FRONTIERS IN EDUCATION, 2024, 9
  • [49] Reply to the letter to the editor 'Surrogate end points for overall survival. Festina lente (more haste, less speed)' by Braillon
    Maeda, H.
    Kurokawa, T.
    ANNALS OF ONCOLOGY, 2015, 26 (04) : 818 - 819
  • [50] Questioning the proverb 'more haste, less speed': classic versus metabarcoding approaches for the diet study of a remote island endemic gecko
    Gil, Vanessa
    Pinho, Catarina J.
    Aguiar, Carlos A. S.
    Jardim, Carolina
    Rebelo, Rui
    Vasconcelos, Raquel
    PEERJ, 2020, 8