Skip to content
AtlassianGHSA-4xqx-pqpj-9fqw

gajira-create GitHub action vulnerable to arbitrary code execution

HighCVE-2020-14188 · Published Oct 28, 2020 · updated Dec 18, 2020

### Impact An attacker can execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue. ### Patches This issue is patched in gajira-create version 2.0.1. ### Workarounds There are no known workarounds. ### References [GitHub Security Lab advisory GHSL-2020-172](https://securitylab.github.com/advisories/GHSL-2020-172-gajira-create-action)

GitHub advisory

Affected versions

PackageAffectedFixed in
gajira-create
Product
< 2.0.12.0.1
Details and references

More Atlassian advisories

All Atlassian
Advisory
Atlassian Bamboo Data Center: improper authorization
High7.6Aug 18
Atlassian Crowd Data Center: improper authentication
High8.8Aug 18
Atlassian Confluence Data Center: information disclosure
High8.2Jul 21
Atlassian Confluence Data Center: denial of service
High7.1Jul 21
Atlassian Sourcetree for Mac: remote code execution
High7.1Jul 21
gajira-comment GitHub action vulnerable to arbitrary code execution
HighOct 28, 2020

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.