The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue comment.
Advisories
Source ID Title
EUVD EUVD EUVD-2020-6345 The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue comment.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: atlassian

Published:

Updated: 2024-09-16T20:13:22.226Z

Reserved: 2020-06-16T00:00:00

Link: CVE-2020-14189

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-11-09T22:15:12.210

Modified: 2024-11-21T05:02:50.060

Link: CVE-2020-14189

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses