Логотип exploitDog
bind:CVE-2024-52308
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-52308

Количество 7

Количество 7

ubuntu логотип

CVE-2024-52308

около 1 года назад

The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ssh` or `gh codespace logs` commands. This has been patched in the cli v2.62.0. Developers connect to remote codespaces through an SSH server running within the devcontainer, which is generally provided through the [default devcontainer image]( https://docs.github.com/en/codespaces/setting-up-your-project-for-codespaces/adding-a-dev-container-... https://docs.github.com/en/codespaces/setting-up-your-project-for-codespaces/adding-a-dev-container-configuration/introduction-to-dev-containers#using-the-default-dev-container-configuration) . GitHub CLI [retrieves SSH connection details]( https://github.com/cli/cli/blob/30066b0042d0c5928d959e288144300cb28196c9/internal/codespaces/rpc/inv... https://github.com/cli/cli/blob/30066b0042d0c5928d959e288144300cb28196c9/internal/codespaces/rpc/invoker.go#L230-L244 ), such as remote username, which is u...

CVSS3: 8
EPSS: Низкий
nvd логотип

CVE-2024-52308

около 1 года назад

The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ssh` or `gh codespace logs` commands. This has been patched in the cli v2.62.0. Developers connect to remote codespaces through an SSH server running within the devcontainer, which is generally provided through the [default devcontainer image]( https://docs.github.com/en/codespaces/setting-up-your-project-for-codespaces/adding-a-dev-container-... https://docs.github.com/en/codespaces/setting-up-your-project-for-codespaces/adding-a-dev-container-configuration/introduction-to-dev-containers#using-the-default-dev-container-configuration) . GitHub CLI [retrieves SSH connection details]( https://github.com/cli/cli/blob/30066b0042d0c5928d959e288144300cb28196c9/internal/codespaces/rpc/inv... https://github.com/cli/cli/blob/30066b0042d0c5928d959e288144300cb28196c9/internal/codespaces/rpc/invoker.go#L230-L244 ), such as remote username, which is use

CVSS3: 8
EPSS: Низкий
msrc логотип

CVE-2024-52308

около 1 года назад

CVSS3: 9.6
EPSS: Низкий
debian логотип

CVE-2024-52308

около 1 года назад

The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code ...

CVSS3: 8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:0021-1

около 1 года назад

Security update for gh

EPSS: Низкий
github логотип

GHSA-p2h2-3vg9-4p87

около 1 года назад

Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer

CVSS3: 8
EPSS: Низкий
fstec логотип

BDU:2024-10385

около 1 года назад

Уязвимость интерфейса командной строки CLI платформы для совместной разработки GitHub, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

CVSS3: 8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-52308

The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ssh` or `gh codespace logs` commands. This has been patched in the cli v2.62.0. Developers connect to remote codespaces through an SSH server running within the devcontainer, which is generally provided through the [default devcontainer image]( https://docs.github.com/en/codespaces/setting-up-your-project-for-codespaces/adding-a-dev-container-... https://docs.github.com/en/codespaces/setting-up-your-project-for-codespaces/adding-a-dev-container-configuration/introduction-to-dev-containers#using-the-default-dev-container-configuration) . GitHub CLI [retrieves SSH connection details]( https://github.com/cli/cli/blob/30066b0042d0c5928d959e288144300cb28196c9/internal/codespaces/rpc/inv... https://github.com/cli/cli/blob/30066b0042d0c5928d959e288144300cb28196c9/internal/codespaces/rpc/invoker.go#L230-L244 ), such as remote username, which is u...

CVSS3: 8
6%
Низкий
около 1 года назад
nvd логотип
CVE-2024-52308

The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using `gh codespace ssh` or `gh codespace logs` commands. This has been patched in the cli v2.62.0. Developers connect to remote codespaces through an SSH server running within the devcontainer, which is generally provided through the [default devcontainer image]( https://docs.github.com/en/codespaces/setting-up-your-project-for-codespaces/adding-a-dev-container-... https://docs.github.com/en/codespaces/setting-up-your-project-for-codespaces/adding-a-dev-container-configuration/introduction-to-dev-containers#using-the-default-dev-container-configuration) . GitHub CLI [retrieves SSH connection details]( https://github.com/cli/cli/blob/30066b0042d0c5928d959e288144300cb28196c9/internal/codespaces/rpc/inv... https://github.com/cli/cli/blob/30066b0042d0c5928d959e288144300cb28196c9/internal/codespaces/rpc/invoker.go#L230-L244 ), such as remote username, which is use

CVSS3: 8
6%
Низкий
около 1 года назад
msrc логотип
CVSS3: 9.6
6%
Низкий
около 1 года назад
debian логотип
CVE-2024-52308

The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code ...

CVSS3: 8
6%
Низкий
около 1 года назад
suse-cvrf логотип
openSUSE-SU-2025:0021-1

Security update for gh

6%
Низкий
около 1 года назад
github логотип
GHSA-p2h2-3vg9-4p87

Connecting to a malicious Codespaces via GH CLI could allow command execution on the user's computer

CVSS3: 8
6%
Низкий
около 1 года назад
fstec логотип
BDU:2024-10385

Уязвимость интерфейса командной строки CLI платформы для совместной разработки GitHub, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольный код

CVSS3: 8
6%
Низкий
около 1 года назад

Уязвимостей на страницу