Skip to content
GitHubGHSA-x4gx-f2xv-6wj9

Arbitrary File Overwrite in CodeQL versions less than 2.18.1

HighCVE-2023-4759 · Published Jul 25, 2024 · updated Jul 26, 2024

### Summary CodeQL versions before 2.18.1 have a dependency on Eclipse JGit versions `4.7.9.201904161809` and earlier, and so are vulnerable to CVE-2023-4759 in specific scenarios. CodeQL 2.18.1 fixes the vulnerability by upgrading its dependency to Eclipse JGit version `6.10.0.202406032230`, which contains a fix for CVE-2023-4759. ### Impact If a CodeQL database is created using a code scanning configuration that specifies the use of custom queries from an untrusted repository ([docs](https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning#running-additional-queries)), and the machine where the database is used has a case-insensitive filesystem, the Git checkout of the specified custom query repository could override arbitrary local files on the filesystem. This doesn't affect users of the CodeQL extension for VS Code or users who don't specify custom queries in their code scanning configurations. ### Patches The problem is fixed in release 2.18.1 of the CLI. Users creating databases manually should update to the latest version of the CLI. Update process: - Customers using the def...

GitHub advisory

Affected versions

PackageAffectedFixed in
codeql-cli-binaries
Product
< 2.18.12.18.1
Details and references

### Summary CodeQL versions before 2.18.1 have a dependency on Eclipse JGit versions `4.7.9.201904161809` and earlier, and so are vulnerable to CVE-2023-4759 in specific scenarios. CodeQL 2.18.1 fixes the vulnerability by upgrading its dependency to Eclipse JGit version `6.10.0.202406032230`, which contains a fix for CVE-2023-4759. ### Impact If a CodeQL database is created using a code scanning configuration that specifies the use of custom queries from an untrusted repository ([docs](https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning#running-additional-queries)), and the machine where the database is used has a case-insensitive filesystem, the Git checkout of the specified custom query repository could override arbitrary local files on the filesystem. This doesn't affect users of the CodeQL extension for VS Code or users who don't specify custom queries in their code scanning configurations. ### Patches The problem is fixed in release 2.18.1 of the CLI. Users creating databases manually should update to the latest version of the CLI. Update process: - Customers using the default settings for code scanning on GitHub.com do not need to take any action to upgrade to this version. - Customers using a specific tools version in code scanning advanced setup workflows on GitHub.com may optionally choose to update this tools URL, or remove the field to use the latest version of CodeQL by default. - Customers on GitHub Enterprise Server may optionally choose to upgrade the version of CodeQL used in their code scanning Actions workflows using GitHub Connect or the CodeQL Action Sync Tool - see [this documentation](https://docs.github.com/en/enterprise-server@3.13/admin/code-security/managing-github-advanced-security-for-your-enterprise/configuring-code-scanning-for-your-appliance) for more information. - Customers using the CodeQL CLI in a third-party CI system may optionally choose to update to the latest version of CodeQL. ### Workarounds - When specifying custom queries, instead of using a repository reference within a configuration file, clone the custom query repository manually and use a local path to this clone in the configuration. - Disable symbolic links on the local filesystem. ### References - CVE-2023-4759 - https://nvd.nist.gov/vuln/detail/CVE-2023-4759 - https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/customizing-your-advanced-setup-for-code-scanning#running-additional-queries

Severity from
GitHub (reviewed advisory)
Weakness
CWE-59, CWE-178

More GitHub advisories

All GitHub
Advisory
GitHub Enterprise Server: path traversal
High8.6Jul 17
GitHub Enterprise Server: denial of service
Medium5.7Jul 17
GitHub Enterprise Server: improper authorization
Medium5.3Jul 1
CSP directive injection via sandbox, plugin_types, and report_to when given untrusted input
Medium4.7Jun 3
GitHub PAT written to debug artifacts
HighJan 24, 2025
Limited data exfiltration in CodeQL CLI
Low2.7Feb 22, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.