Ubuntu Security Update USN-8012-1: GitHub CLI vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,787
Reaction score
74
Credits
-1,257
It was discovered that GitHub CLI could behave unexpectedly if users downloaded a malicious GitHub Actions workflow artifact through gh run download. An attacker could possibly use this issue to create or overwrite files in unintended directories. (CVE-2024-54132) It was discovered that GitHub CLI could behave unexpectedly when cloning repositories containing git submodules hosted outside of GitHub.com and ghe.com. An attacker could possibly use this issue to gather authentication tokens. (CVE-2024-53858)

Continue reading...
 


Follow Linux.org

Members online


Top