Overview

For 7 days Travis CI pull requests were including secure environment vars in public repositories.

Impact

Signing keys, access credentials and API tokens may have been leaked, which could be used to gain a foothold onto thousands of customer networks.

Affected Products

Public repositories using TravisCI.

Containment, Mitigations & Remediations

Travis CI recommend you rotate your secrets. They have not reached out to affected parties or made any serious attempt to inform the public about the issue.

Based on the vendor response, the security researchers who found the vulnerability recommend switching away from Travis CI altogether.

Threat Landscape

In 2019 the company was acquired and a large portion of their development team was fired.

Mitre Methodologies

T1555 – Credentials from Password Stores

Further Information

Travis CI Security Bulletin
Carmen H. Andoh on Twitter

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content