Azure, GitHub, GitLab, BitBucket mass-revoke SSH keys following bug report
Image: Chunli Ju
Catalin Cimpanu October 12, 2021

Azure, GitHub, GitLab, BitBucket mass-revoke SSH keys following bug report

Azure, GitHub, GitLab, BitBucket mass-revoke SSH keys following bug report

Microsoft, GitHub, GitLab, and BitBucket —four of today’s largest code hosting portals— have initiated mass revocations of SSH keys on Monday after the discovery of a vulnerability in a popular Git software client named GitKraken.

The mass revocations come at the request of Arizona-based software company Axosoft, which developed GitKraken and is the one who found the security flaw in its own software.

In a blog post on Monday, Axosoft explained that versions 7.6.x, 7.7.x, and 8.0.0 of its GitKraken app used a library named “keypair” to generated SSH keys to allow developers to connect their GitKraken app to accounts on Azure DevOps, GitHub, GitLab, BitBucket, or other remote Git source code hosting servers.

But Axosoft said that older versions of this library generated RSA keys with low entropy, meaning that attackers could use the library, under certain conditions, to generate duplicate SSH keys.

The attacker could then use these keys to access a user’s account and steal proprietary source code.

Axosoft said that as soon as it learned of the issue, it replaced the keypair library inside the GitKraken app, released version 8.0.1, and notified the four platforms.

Shortly after Axosoft’s blog post, the security teams of Azure DevOpsGitHubGitLab, and Atlassian’s BitBucket have started revoking all SSH keys connected to accounts where the GitKraken app was used to synchronize source code.

The four platforms are now asking users to generate new SSH keys using a different Git client or using an updated GitKraken app.

Both Axosoft and the four platforms said they haven’t found evidence that attackers used this bug to compromise accounts — so far.

In addition, GitHub also asked the developers of other software applications —not only Git clients— to check and see if they are using the vulnerable keypair library in their apps, and update their code accordingly. The keypair library also received a security update on Monday.

Catalin Cimpanu is a cybersecurity reporter for The Record. He previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.