Vulnerability Description
The preprocessArgs function in the Atlassian gajira-create GitHub Action before version 2.0.1 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Jira Create | < 2.0.1 |
References
- https://github.com/atlassian/gajira-create/security/advisories/GHSA-4xqx-pqpj-9fThird Party Advisory
- https://github.com/atlassian/gajira-create/security/advisories/GHSA-4xqx-pqpj-9fThird Party Advisory
FAQ
What is CVE-2020-14188?
CVE-2020-14188 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The preprocessArgs function in the Atlassian gajira-create GitHub Action before version 2.0.1 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a speciall...
How severe is CVE-2020-14188?
CVE-2020-14188 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-14188?
Check the references section above for vendor advisories and patch information. Affected products include: Atlassian Jira Create.