PT-2023-11902 · Unknown · Ons Digital Ras Collection Instrument

CVE-2020-36762

·

Published

2023-07-18

·

Updated

2024-05-17

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ONS Digital RAS Collection Instrument versions up to 2.0.27
Description A critical issue was found in the function jobs of the file .github/workflows/comment.yml. The manipulation of the argument $COMMENT BODY leads to os command injection.
Recommendations For ONS Digital RAS Collection Instrument versions up to 2.0.27, upgrade to version 2.0.28 to address this issue. As a temporary workaround, consider restricting the use of the $COMMENT BODY argument in the jobs function until the upgrade is applied.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-36762

Affected Products

Ons Digital Ras Collection Instrument