Bullfrog is a GithHb Action to block unauthorized outbound traffic in GitHub workflows. Prior to version 0.8.4, using tcp breaks blocking and allows DNS exfiltration. This can result in sandbox bypass. Version 0.8.4 fixes the issue.
References
Link | Resource |
---|---|
https://github.com/bullfrogsec/bullfrog/commit/ae7744ae4b3a6f8ffc2e49f501e30bf1a43d4671 | Patch |
https://github.com/bullfrogsec/bullfrog/releases/tag/v0.8.4 | Release Notes |
https://github.com/bullfrogsec/bullfrog/security/advisories/GHSA-m32f-fjw2-37v3 | Exploit Vendor Advisory |
https://github.com/bullfrogsec/bullfrog/security/advisories/GHSA-m32f-fjw2-37v3 | Exploit Vendor Advisory |
Configurations
History
11 Jul 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-14 16:15
Updated : 2025-07-11 16:15
NVD link : CVE-2025-47775
Mitre link : CVE-2025-47775
CVE.ORG link : CVE-2025-47775
JSON object : View
Products Affected
bullfrogsec
- bullfrog
CWE