Kiwi TCMS has command injection vulnerability in changelog.yml CI workflow
CVE-2023-30628
8.8HIGH
What is CVE-2023-30628?
Kiwi TCMS, an open source test management system, is susceptible to command injection due to improper handling of the github.head_ref field in the changelog.yml workflow. Attackers can exploit this vulnerability by injecting malicious commands, such as assigning a specific payload to the github.head_ref, potentially leading to unauthorized command execution within the repository. The lack of permission restrictions allows attackers to write to the repository, enhancing the risk. Fixes for this issue have been implemented in specific commits of both the Kiwi TCMS and Enterprise repositories.
Affected Version(s)
Kiwi <= 12.2
