A RetroSearch Logo

Home - News ( United States | United Kingdom | Italy | Germany ) - Football scores

Search Query:

Showing content from https://github.com/github/codeql-cli-binaries/security/advisories/GHSA-x4gx-f2xv-6wj9 below:

Arbitrary File Overwrite in CodeQL versions less than 2.18.1 · Advisory · github/codeql-cli-binaries · GitHub

Summary

CodeQL versions before 2.18.1 have a dependency on Eclipse JGit versions 4.7.9.201904161809 and earlier, and so are vulnerable to CVE-2023-4759 in specific scenarios.
CodeQL 2.18.1 fixes the vulnerability by upgrading its dependency to Eclipse JGit version 6.10.0.202406032230, which contains a fix for CVE-2023-4759.

Impact

If a CodeQL database is created using a code scanning configuration that specifies the use of custom queries from an untrusted repository (docs), and the machine where the database is used has a case-insensitive filesystem, the Git checkout of the specified custom query repository could override arbitrary local files on the filesystem.

This doesn't affect users of the CodeQL extension for VS Code or users who don't specify custom queries in their code scanning configurations.

Patches

The problem is fixed in release 2.18.1 of the CLI.

Users creating databases manually should update to the latest version of the CLI.

Update process:

Workarounds References

RetroSearch is an open source project built by @garambo | Open a GitHub Issue

Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo

HTML: 3.2 | Encoding: UTF-8 | Version: 0.7.4