Input validation error in GitHub CLI - CVE-2024-52308
Published: November 27, 2024
Vulnerability identifier: #VU100996
CSH Severity: High
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-52308
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to the way GitHub CLI handles SSH connection details when executing commands. A remote user can supply a specially crafted devcontainer that can inject and execute arbitrary commands on the system with elevated privileges.
Affected software
GitHub CLI
Ubuntu
gh (Ubuntu package)
Ubuntu
gh (Ubuntu package)
How to mitigate CVE-2024-52308
Install updates from vendor's website.
GitHub CLI - update to 2.62.0
gh (Ubuntu package) - addressed in versions Ubuntu Pro, 2.46.0-1ubuntu0.2
gh (Ubuntu package) - addressed in versions Ubuntu Pro, 2.46.0-1ubuntu0.2