gajira-create GitHub action vulnerable to arbitrary code execution
Critical severity
GitHub Reviewed
Published
Oct 28, 2020
in
atlassian/gajira-create
•
Updated Jan 29, 2023
Description
Published by the National Vulnerability Database
Nov 9, 2020
Published to the GitHub Advisory Database
Oct 7, 2022
Reviewed
Oct 7, 2022
Last updated
Jan 29, 2023
Impact
An attacker can execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue.
Patches
This issue is patched in gajira-create version 2.0.1.
Workarounds
There are no known workarounds.
References
GitHub Security Lab advisory GHSL-2020-172
References