GHSA-4xqx-pqpj-9fqw
Dashboard / Vulnerabilities / GHSA-4xqx-pqpj-9fqw
Summary: gajira-create GitHub action vulnerable to arbitrary code execution
Details: ### Impact An attacker can execute arbitrary code in the context of a GitHub runner by creating a specially crafted GitHub issue. ### Patches This issue is patched in gajira-create version 2.0.1. ### Workarounds There are no known workarounds. ### References [GitHub Security Lab advisory GHSL-2020-172](https://securitylab.github.com/advisories/GHSL-2020-172-gajira-create-action)
References: https://github.com/atlassian/gajira-create/security/advisories/GHSA-4xqx-pqpj-9fqw, https://nvd.nist.gov/vuln/detail/CVE-2020-14188, https://github.com/atlassian/gajira-create
Affected packages
Package
Name: atlassian/gajira-create
Purl:
Affected ranges
Type: ECOSYSTEM
Events:
