CVE-2023-42798 Information
Sep 23, 2023
cve
Description
AutomataCI is a template git repository equipped with a native built-in semi-autonomous CI tools. An issue in versions 1.4.1 and below can let a release job reset the git root repository to the first commit. Version 1.5.0 has a patch for this issue. As a workaround make sure the PROJECT_PATH_RELEASE (e.g. releases/) directory is manually and actually git cloned properly making it a different git repostiory from the root git repository.
Reference
https://github.com/ChewKeanHo/AutomataCI/issues/93 https://github.com/ChewKeanHo/AutomataCI/security/advisories/GHSA-6q23-vhhg-8h89
Share on: