USN-7130-1: GitHub CLI vulnerability
It was discovered that GitHub CLI incorrectly handled username validation. An attacker could possibly use this issue to perform remote code execution if the user connected to a malicious server. (CVE-2024-52308)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7130-1?
The severity of USN-7130-1 is critical due to the potential for remote code execution.
How do I fix USN-7130-1?
To fix USN-7130-1, update to the latest version of the 'gh' package, specifically to version 2.46.0-1ubuntu0.2 for Ubuntu 24.10 or 2.45.0-1ubuntu0.2+esm1 for Ubuntu 24.04.
What are the potential impacts of USN-7130-1?
The potential impacts of USN-7130-1 include the risk of remote code execution if a user connects to a malicious server.
Which versions of Ubuntu are affected by USN-7130-1?
USN-7130-1 affects Ubuntu 24.10 and Ubuntu 24.04 with specific versions of the 'gh' package.
Is USN-7130-1 a common vulnerability?
USN-7130-1 is significant as it addresses a newly discovered vulnerability in the GitHub CLI that could lead to severe security risks.