Wiz disclosed on August 17 that its Red Agent research tool found a flaw in a public Snowflake repository that enabled access to the company’s internal Jira system. The vulnerability affected a GitHub Actions workflow handling issue titles.

According to Wiz, the flaw became live on June 18 and was reported on June 23. Snowflake fixed it that day. In its response included with the research, Snowflake said its investigation found no evidence of unauthorized access.

Wiz says automated security checks missed the injection flaw. Its updated post clarifies that GitHub Copilot contributed to the same pull request but that AI’s involvement in the vulnerable change is unclear. The disclosure therefore does not establish that AI wrote the defective code.

Sources

About Pituchim · Report a correction

Share this story

LinkedIn X Facebook WhatsApp Telegram Reddit Email