Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6q32-hq47-5qq3

Опубликовано: 03 сент. 2024
Источник: github
Github: Прошло ревью
CVSS4: 8.6
CVSS3: 7.3

Описание

@actions/artifact has an Arbitrary File Write via artifact extraction

Impact

Versions of actions/artifact before 2.1.7 are vulnerable to arbitrary file write when using downloadArtifactInternal, downloadArtifactPublic, or streamExtractExternal for extracting a specifically crafted artifact that contains path traversal filenames.

Patches

Upgrade to version 2.1.7 or higher.

References

CVE

CVE-2024-42471

Credits

Justin Taft from Google

Пакеты

Наименование

@actions/artifact

npm
Затронутые версииВерсия исправления

>= 2.0.0, < 2.1.2

2.1.2

EPSS

Процентиль: 90%
0.0583
Низкий

8.6 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.3
nvd
больше 1 года назад

actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.2 or higher. There are no known workarounds for this issue.

EPSS

Процентиль: 90%
0.0583
Низкий

8.6 High

CVSS4

7.3 High

CVSS3

Дефекты

CWE-22