Skip to content

gajira-comment GitHub action vulnerable to arbitrary code execution

High
highvoltag3 published GHSA-hj6w-pm28-h8hf Oct 28, 2020

Package

gajira-comment

Affected versions

< 2.0.2

Patched versions

2.0.2

Description

Impact

An attacker can execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue comment.

Patches

This issue is patched in gajira-comment version 2.0.2.

Workarounds

There are no known workarounds.

References

GitHub Security Lab advisory GHSL-2020-173

Severity

High

CVE ID

CVE-2020-14189

Weaknesses

No CWEs

Credits