PT-2020-14330 · Github · Git-Tag-Annotation-Action

Lowericcornelissen

·

Published

2020-10-26

·

Updated

2020-10-28

·

CVE-2020-15272

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions git-tag-annotation-action versions prior to 1.0.1
Description The issue allows an attacker to execute arbitrary shell commands if they can control the value of the tag input or alter the GITHUB REF environment variable. However, the GITHUB REF environment variable is protected by the GitHub Actions environment, making attacks from this vector unlikely. The estimated number of potentially affected devices is not provided. There is no information about real-world incidents where this issue was exploited.
Recommendations For versions prior to 1.0.1, update to version 1.0.1 or later to resolve the issue. If updating to version 1.0.1 or later is not possible, and the tag input must be used, ensure that its value is not controlled by another Action.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-15272
GHSA-HGX2-4PP9-357G

Affected Products

Git-Tag-Annotation-Action