mirror of
https://github.com/CVEProject/cvelist.git
synced 2025-07-29 05:56:59 +00:00
223 lines
10 KiB
JSON
223 lines
10 KiB
JSON
{
|
|
"data_version": "4.0",
|
|
"data_type": "CVE",
|
|
"data_format": "MITRE",
|
|
"CVE_data_meta": {
|
|
"ID": "CVE-2020-36762",
|
|
"ASSIGNER": "cna@vuldb.com",
|
|
"STATE": "PUBLIC"
|
|
},
|
|
"description": {
|
|
"description_data": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "A vulnerability was found in ONS Digital RAS Collection Instrument up to 2.0.27 and classified as critical. Affected by this issue is the function jobs of the file .github/workflows/comment.yml. The manipulation of the argument $COMMENT_BODY leads to os command injection. Upgrading to version 2.0.28 is able to address this issue. The name of the patch is dcaad2540f7d50c512ff2e031d3778dd9337db2b. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-234248."
|
|
},
|
|
{
|
|
"lang": "deu",
|
|
"value": "Eine Schwachstelle wurde in ONS Digital RAS Collection Instrument bis 2.0.27 gefunden. Sie wurde als kritisch eingestuft. Betroffen davon ist die Funktion jobs der Datei .github/workflows/comment.yml. Durch die Manipulation des Arguments $COMMENT_BODY mit unbekannten Daten kann eine os command injection-Schwachstelle ausgenutzt werden. Ein Aktualisieren auf die Version 2.0.28 vermag dieses Problem zu l\u00f6sen. Der Patch wird als dcaad2540f7d50c512ff2e031d3778dd9337db2b bezeichnet. Als bestm\u00f6gliche Massnahme wird das Einspielen eines Upgrades empfohlen."
|
|
}
|
|
]
|
|
},
|
|
"problemtype": {
|
|
"problemtype_data": [
|
|
{
|
|
"description": [
|
|
{
|
|
"lang": "eng",
|
|
"value": "CWE-78 OS Command Injection",
|
|
"cweId": "CWE-78"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
},
|
|
"affects": {
|
|
"vendor": {
|
|
"vendor_data": [
|
|
{
|
|
"vendor_name": "ONS Digital",
|
|
"product": {
|
|
"product_data": [
|
|
{
|
|
"product_name": "RAS Collection Instrument",
|
|
"version": {
|
|
"version_data": [
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.0"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.1"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.2"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.3"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.4"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.5"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.6"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.7"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.8"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.9"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.10"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.11"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.12"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.13"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.14"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.15"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.16"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.17"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.18"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.19"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.20"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.21"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.22"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.23"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.24"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.25"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.26"
|
|
},
|
|
{
|
|
"version_affected": "=",
|
|
"version_value": "2.0.27"
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
}
|
|
]
|
|
}
|
|
},
|
|
"references": {
|
|
"reference_data": [
|
|
{
|
|
"url": "https://vuldb.com/?id.234248",
|
|
"refsource": "MISC",
|
|
"name": "https://vuldb.com/?id.234248"
|
|
},
|
|
{
|
|
"url": "https://vuldb.com/?ctiid.234248",
|
|
"refsource": "MISC",
|
|
"name": "https://vuldb.com/?ctiid.234248"
|
|
},
|
|
{
|
|
"url": "https://github.com/ONSdigital/ras-collection-instrument/pull/199",
|
|
"refsource": "MISC",
|
|
"name": "https://github.com/ONSdigital/ras-collection-instrument/pull/199"
|
|
},
|
|
{
|
|
"url": "https://github.com/ONSdigital/ras-collection-instrument/commit/dcaad2540f7d50c512ff2e031d3778dd9337db2b",
|
|
"refsource": "MISC",
|
|
"name": "https://github.com/ONSdigital/ras-collection-instrument/commit/dcaad2540f7d50c512ff2e031d3778dd9337db2b"
|
|
},
|
|
{
|
|
"url": "https://github.com/ONSdigital/ras-collection-instrument/releases/tag/2.0.28",
|
|
"refsource": "MISC",
|
|
"name": "https://github.com/ONSdigital/ras-collection-instrument/releases/tag/2.0.28"
|
|
}
|
|
]
|
|
},
|
|
"credits": [
|
|
{
|
|
"lang": "en",
|
|
"value": "VulDB GitHub Commit Analyzer"
|
|
}
|
|
],
|
|
"impact": {
|
|
"cvss": [
|
|
{
|
|
"version": "3.1",
|
|
"baseScore": 5.5,
|
|
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
|
|
"baseSeverity": "MEDIUM"
|
|
},
|
|
{
|
|
"version": "3.0",
|
|
"baseScore": 5.5,
|
|
"vectorString": "CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L",
|
|
"baseSeverity": "MEDIUM"
|
|
},
|
|
{
|
|
"version": "2.0",
|
|
"baseScore": 5.2,
|
|
"vectorString": "AV:A/AC:L/Au:S/C:P/I:P/A:P"
|
|
}
|
|
]
|
|
}
|
|
} |