{"id":"GHSA-3r32-cp7v-5wq4","summary":"Code injection in ansible semaphore","details":"An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbitrary code via a crafted payload to the extra variables parameter.","aliases":["CVE-2023-39059"],"modified":"2024-10-02T18:37:59Z","published":"2023-08-29T00:32:03Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-08-30T20:43:00Z","nvd_published_at":"2023-08-28T22:15:08Z","cwe_ids":["CWE-94"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-39059"},{"type":"WEB","url":"https://gist.github.com/Alevsk/1757da24c5fb8db735d392fd4146ca3a"},{"type":"PACKAGE","url":"https://github.com/ansible-semaphore/semaphore"},{"type":"WEB","url":"https://www.alevsk.com/2023/07/a-quick-story-of-security-pitfalls-with-execcommand-in-software-integrations"}],"affected":[{"package":{"name":"github.com/ansible-semaphore/semaphore","ecosystem":"Go","purl":"pkg:golang/github.com/ansible-semaphore/semaphore"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"2.8.90"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/08/GHSA-3r32-cp7v-5wq4/GHSA-3r32-cp7v-5wq4.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}