Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

CVE-2023-28430

7.3 · HIGH
Published Mar 27, 2023 onesignal CWE-77 EPSS 0.91% (57th pctl)

Overview

CVE-2023-28430 is a high-severity vulnerability affecting onesignal react-native-onesignal. It was published on March 27, 2023 and has a CVSS 3.1 base score of 7.3 (HIGH).

This vulnerability has a CVSS 3.1 base score of 7.3, rated HIGH. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

Technical Description

OneSignal is an email, sms, push notification, and in-app message service for mobile apps.The Zapier.yml workflow is triggered on issues (types: [closed]) (i.e., when an Issue is closed). The workflow starts with full write-permissions GitHub repository token since the default workflow permissions on Organization/Repository level are set to read-write. This workflow runs the following step with data controlled by the comment `(${{ github.event.issue.title }} – the full title of the Issue)`, allowing an attacker to take over the GitHub Runner and run custom commands, potentially stealing any secret (if used), or altering the repository. This issue was found with CodeQL using javascript’s Expression injection in Actions query. This issue has been addressed in the repositories github action. No actions are required by users. This issue is also tracked as `GHSL-2023-051`.

Remediation

Check the references section for vendor advisories and patches from onesignal. Update react-native-onesignal to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

Affected Products

Vendor Product Versions Status
onesignal react-native-onesignal >= 0, < 4.5.1 Affected

Frequently Asked Questions

What is CVE-2023-28430?

CVE-2023-28430 is a high-severity vulnerability affecting onesignal react-native-onesignal. It was published on March 27, 2023 and has a CVSS 3.1 base score of 7.3 (HIGH).

How severe is CVE-2023-28430?

This vulnerability has a CVSS 3.1 base score of 7.3, rated HIGH. It can be exploited remotely over the network. Some level of privileges is required for exploitation.

How do I fix or remediate CVE-2023-28430?

Check the references section for vendor advisories and patches from onesignal. Update react-native-onesignal to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.

How can CyberStrike help with CVE-2023-28430?

CyberStrike's AI-powered security agents can automatically detect CVE-2023-28430 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.