PT-2020-13920 · Atlassian · Gajira-Create Github Action

Jarlob

·

Published

2020-11-09

·

Updated

2022-10-07

·

CVE-2020-14188

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Atlassian gajira-create GitHub Action versions prior to 2.0.1
Description The issue allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue. This is due to a problem in the preprocessArgs function. An attacker can exploit this to run arbitrary code.
Recommendations For versions prior to 2.0.1, update to version 2.0.1 to resolve the issue. As a temporary workaround, consider restricting the creation of GitHub issues to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2020-14188
GHSA-4XQX-PQPJ-9FQW

Affected Products

Gajira-Create Github Action