Github Labs
Explore 1 lab in Github.
Insufficient flow control mechanisms occur when CI/CD pipelines lack restrictions on how data, artefacts, and jobs flow between stages or components. Without strong boundaries and policies, adversaries can manipulate the flow to introduce malicious artefacts, trigger unauthorised jobs, or exfiltrate sensitive data. This risk often manifests as pipelines that allow unreviewed changes to flow directly into production, workflows that execute without approval gates, or jobs that share unprotected workspaces and artefacts across stages.
Examples include:
Select a language to explore available labs for this vulnerability.
Try adjusting your language filter.
Want to skill-up in secure coding and AppSec? Try SecDim Wargames to learn how to find, hack and fix security vulnerabilities inspired by real-world incidents.
Join our secure coding and AppSec community. A discussion board to share and discuss all aspects of secure programming, AppSec, DevSecOps, fuzzing, cloudsec, AIsec code review, and more.
Read more