Kiwi TCMS has command injection vulnerability in changelog.yml CI workflow
CVE-2023-30628

8.8HIGH

Key Information:

Vendor

Kiwitcms

Status
Vendor
CVE Published:
24 April 2023

What is CVE-2023-30628?

Kiwi TCMS, an open source test management system, is susceptible to command injection due to improper handling of the github.head_ref field in the changelog.yml workflow. Attackers can exploit this vulnerability by injecting malicious commands, such as assigning a specific payload to the github.head_ref, potentially leading to unauthorized command execution within the repository. The lack of permission restrictions allows attackers to write to the repository, enhancing the risk. Fixes for this issue have been implemented in specific commits of both the Kiwi TCMS and Enterprise repositories.

Affected Version(s)

Kiwi <= 12.2

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.