AutomataCI Release Job Can Revert Repo to First Commit
CVE-2023-42798

8.2HIGH

Key Information:

Vendor

Chewkeanho

Vendor
CVE Published:
22 September 2023

What is CVE-2023-42798?

An issue in the AutomataCI tool can cause a release job to inadvertently reset the git root repository to its first commit, compromising the integrity of your version control. This vulnerability affects versions 1.4.1 and earlier, but version 1.5.0 has been released to address this issue. As a precaution, users are advised to ensure that the 'PROJECT_PATH_RELEASE' directory is properly cloned as a separate git repository to mitigate this risk.

Affected Version(s)

AutomataCI < 1.5.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.