Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

Security Vulnerabilities in AI-Powered Git Pull Request Tools - A Case Study of Qodo Merge

media.ccc.de via YouTube

Overview

Coursera Flash Sale
40% Off Coursera Plus for 3 Months!
Grab it
Watch a 41-minute conference talk from the 38th Chaos Communication Congress (38C3) exploring critical security vulnerabilities in Qodo Merge, an AI-powered tool for handling git pull requests. Discover how this increasingly popular open-source tool, despite its helpful features like pull request analysis and code improvement suggestions, contains serious security flaws that could lead to privilege escalation on Gitlab, unauthorized write access to Github repositories, and exposure of repository secrets. Learn about the widespread impact on major projects, including government repositories, automotive industry projects, and blockchain systems. Understand the technical details of how Qodo Merge operates, the specific exploitation methods, and essential remediation steps to protect repositories. The presentation also addresses the challenges faced when attempting to report these vulnerabilities and examines the current security posture of the project.

Syllabus

38C3 - AI Meets Git: Unmasking Security Flaws in Qodo Merge

Taught by

media.ccc.de

Reviews

Start your review of Security Vulnerabilities in AI-Powered Git Pull Request Tools - A Case Study of Qodo Merge

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.