PT-2022-24816 · Some Natalie · Ghas-To-Csv

Aegilops

+1

·

Published

2022-09-16

·

Updated

2022-09-21

·

CVE-2022-39217

CVSS v3.1

5.8

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions some-natalie/ghas-to-csv versions prior to v1
Description The issue arises from the GitHub Action creating a CSV file without sanitizing the output of the APIs. If an alert is dismissed or any other custom field contains executable code or formulas, it might be run when an endpoint opens that CSV file in a spreadsheet program.
Recommendations For versions prior to v1, update to version v1 or later to resolve the issue. As a temporary workaround, consider avoiding the use of custom fields that may contain executable code or formulas in the GitHub Advanced Security API until the update is applied.

Exploit

Fix

Special Elements Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-39217
GHSA-634P-93H9-92VH

Affected Products

Ghas-To-Csv