Vulnerability Description
The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue comment.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Atlassian | Jira Comment | < 2.0.2 |
References
- https://github.com/atlassian/gajira-comment/security/advisories/GHSA-hj6w-pm28-hThird Party Advisory
- https://github.com/atlassian/gajira-comment/security/advisories/GHSA-hj6w-pm28-hThird Party Advisory
FAQ
What is CVE-2020-14189?
CVE-2020-14189 is a vulnerability with a CVSS score of 9.8 (CRITICAL). The execute function in in the Atlassian gajira-comment GitHub Action before version 2.0.2 allows remote attackers to execute arbitrary code in the context of a GitHub runner by creating a specially c...
How severe is CVE-2020-14189?
CVE-2020-14189 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2020-14189?
Check the references section above for vendor advisories and patch information. Affected products include: Atlassian Jira Comment.