AtlassianGHSA-hj6w-pm28-h8hf
gajira-comment GitHub action vulnerable to arbitrary code execution
HighCVE-2020-14189 · Published Oct 28, 2020 · updated Dec 18, 2020
### Impact An attacker can execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue comment. ### Patches This issue is patched in gajira-comment version 2.0.2. ### Workarounds There are no known workarounds. ### References [GitHub Security Lab advisory GHSL-2020-173](https://securitylab.github.com/advisories/GHSL-2020-173-gajira-comment-action)
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| gajira-comment Product | < 2.0.2 | 2.0.2 |
Details and references
- Severity from
- GitHub (reviewed advisory)
More Atlassian advisories
All Atlassian| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 18 | Atlassian Bamboo Data Center: improper authorization | High7.6 | No fix yet |
| Aug 18 | Atlassian Crowd Data Center: improper authentication | High8.8 | No fix yet |
| Jul 21 | Atlassian Confluence Data Center: information disclosure | High8.2 | No fix yet |
| Jul 21 | Atlassian Confluence Data Center: denial of service | High7.1 | No fix yet |
| Jul 21 | Atlassian Sourcetree for Mac: remote code execution | High7.1 | No fix yet |
| Oct 282020 | gajira-create GitHub action vulnerable to arbitrary code execution | High | 2.0.1 |