Impact
The vulnerability resides in the GitHub App provider component of Pipelines-as-Code. Prior to releases 0.37.8, 0.39.6, 0.42.1, and 0.48.0, the application accepts the X‑GitHub‑Enterprise‑Host header as the API host while handling webhook events that include an installation.id. This check occurs before validating the webhook’s signature or verifying that the host in the signed payload matches the repository URL. An unauthenticated attacker who can reach the webhook endpoint can supply an arbitrary header value, causing the controller to issue a locally signed GitHub App JWT to the attacker‑controlled host. The short‑lived JWT can then be used to mint installation access tokens for the target repository during its validity window, limited only by the scopes granted to the GitHub App. The incoming webhook installation‑lookup path is also affected, but exploiting that path requires the valid incoming webhook secret for the target Repository CR. Consequently, an attacker could obtain privileged tokens that grant repository access and CI/CD capabilities.
Affected Systems
All releases of tektoncd:pipelines-as-code published before version 0.37.8, 0.39.6, 0.42.1, and 0.48.0 are affected. Users running any of those earlier versions, regardless of whether the GitHub App is installed, are within scope. The vulnerability is tied to the webhook endpoint of the application and does not depend on the presence of any specific configuration beyond the exposed header.
Risk and Exploitability
The CVSS score of 8.2 classifies this issue as high severity. The EPSS score is 0.00184, indicating a very low but nonzero probability of exploitation; however, the lack of authentication requirements and the potential to acquire installation tokens make the risk significant. The vulnerability is not listed in the CISA KEV catalog, indicating that no well‑known public exploits are documented. Likely attack vectors involve sending a crafted webhook payload that includes a forged X‑GitHub‑Enterprise‑Host header; if the JWT is captured, it may be used to mint tokens and gain repository or pipeline access.
OpenCVE Enrichment
Github GHSA