Skip to content

gajira-create GitHub action vulnerable to arbitrary code execution

High
highvoltag3 published GHSA-4xqx-pqpj-9fqw Oct 28, 2020

Package

gajira-create

Affected versions

< 2.0.1

Patched versions

2.0.1

Description

Impact

An attacker can execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue.

Patches

This issue is patched in gajira-create version 2.0.1.

Workarounds

There are no known workarounds.

References

GitHub Security Lab advisory GHSL-2020-172

Severity

High

CVE ID

CVE-2020-14188

Weaknesses

No CWEs

Credits