Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
cal.com Repository Takeover via pull_request_target Workflow
Vulnerability Description
cal.com (calcom repository, later renamed cal.diy) is affected by a repository takeover vulnerability in its GitHub Actions workflows. The workflow pr.yml uses the pull_request_target trigger with the repository's default write permissions and passes them down to check-types.yml. check-types.yml then performs a 'dangerous' checkout of the attacker-submitted pull request code (via the dangerous-git-checkout action) and subsequently executes it (through yarn install and package.json scripts). An attacker can open a pull request whose code runs arbitrary commands with the repository's write-scoped GITHUB_TOKEN, allowing them to push commits, merge or mutate pull requests, add or delete comments, and delete or force-push branches, thereby compromising the repository. The main branch is affected; no patched version is available.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
Vulnerability Type
在命令中使用的特殊元素转义处理不恰当(命令注入)
Vulnerability Title
calcom cal.diy 命令注入漏洞
Vulnerability Description
calcom cal.diy是calcom的Web中间件。 calcom cal.diy存在命令注入漏洞,该漏洞源于GitHub Actions工作流中pull_request_target触发器的使用,导致攻击者可以通过打开拉取请求运行任意命令,利用仓库的写入权限,进行提交、合并或修改拉取请求、添加或删除评论以及删除或强制推送分支,从而接管仓库。
CVSS Information
N/A
Vulnerability Type
N/A