We've found an issue with Bitbucket cloud, where any user with write permissions has the ability to export the runtime secrets, including workspace / repository / deployment secrets, to an artifact. Like so:
1. A user with write access creates a new branch from the main branch.
2. That user then modifies the bitbucket-pipelines.yml file, and adds a step similar to this:
...
steps:
- printenv | tee output.txt
...
artifacts:
paths:
output.txt
3. Then that user can push the changes, and within that branch execute the step, and download the artifact, revealing all of the secrets.
How do you prevent this kind of leakage?