Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4xqx-pqpj-9fqw

Опубликовано: 07 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

gajira-create GitHub action vulnerable to arbitrary code execution

Impact

An attacker can execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue.

Patches

This issue is patched in gajira-create version 2.0.1.

Workarounds

There are no known workarounds.

References

GitHub Security Lab advisory GHSL-2020-172

Пакеты

Наименование

atlassian/gajira-create

actions
Затронутые версииВерсия исправления

< 2.0.1

2.0.1

EPSS

Процентиль: 84%
0.02136
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
около 5 лет назад

The preprocessArgs function in the Atlassian gajira-create GitHub Action before version 2.0.1 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue.

EPSS

Процентиль: 84%
0.02136
Низкий

9.8 Critical

CVSS3