πŸ” Search
Sign in to post
Self-hosted Coder: check whether you pulled a registry module on Aug 31. no CVE, so nothing will flag it for youhttps://www.reddit.com/r/netsec/comments/1w77oxx/selfhosted_coder_check_whether_you_pulled_a

On Aug 31, rogue origins were added to the Cloudflare pool in front of registry.coder.com . For roughly 14 hours, 07:35–21:45 UTC, the real registry domain served Terraform modules carrying an extra data "external" "telemetry" block that shelled out to dlp-docker.sh and posted your environment to www[.]coder-infra[.]com . Why nothing caught it There's no bad version to pin away from, because the poisoned artifact was served at a legit version. The domain allowlist passed because it was the right domain. And no CVE was assigned, so there's no NVD or OSV record for SCA to match on. The adviso…

0trust.social media

Loading your media...

Pick a GIF β€” Giphy

Loading GIFs...