You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description:
The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using gh codespace ssh or gh codespace logs commands. This has been patched in the cli v2.62.0.
Developers connect to remote codespaces through an SSH server running within the devcontainer, which is generally provided through the default devcontainer image. GitHub CLI [ret...
Advisory CVE-2024-52308 references a vulnerability in the following Go modules:
Description:
The GitHub CLI version 2.6.1 and earlier are vulnerable to remote code execution through a malicious codespace SSH server when using
gh codespace ssh
orgh codespace logs
commands. This has been patched in the cli v2.62.0.Developers connect to remote codespaces through an SSH server running within the devcontainer, which is generally provided through the default devcontainer image. GitHub CLI [ret...
References:
Cross references:
See doc/quickstart.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: