Description
The preprocessArgs function in the Atlassian gajira-create GitHub Action before version 2.0.1 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-7020 | The preprocessArgs function in the Atlassian gajira-create GitHub Action before version 2.0.1 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue. |
Github GHSA |
GHSA-4xqx-pqpj-9fqw | gajira-create GitHub action vulnerable to arbitrary code execution |
References
History
No history.
Status: PUBLISHED
Assigner: atlassian
Published:
Updated: 2024-09-17T04:25:28.696Z
Reserved: 2020-06-16T00:00:00.000Z
Link: CVE-2020-14188
No data.
Status : Modified
Published: 2020-11-09T22:15:12.130
Modified: 2024-11-21T05:02:49.953
Link: CVE-2020-14188
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA