Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qmg3-hpqr-gqvc

Опубликовано: 19 мар. 2025
Источник: github
Github: Прошло ревью
CVSS3: 8.6

Описание

Multiple Reviewdog actions were compromised during a specific time period

Summary

reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs.

Other reviewdog actions that use reviewdog/action-setup@v1 would also be compromised, regardless of version or pinning method:

  • reviewdog/action-shellcheck
  • reviewdog/action-composite-template
  • reviewdog/action-staticcheck
  • reviewdog/action-ast-grep
  • reviewdog/action-typos

Details

Malicious commit: https://github.com/reviewdog/action-setup/commit/f0d342d fix/retag via version upgrade: https://github.com/reviewdog/action-setup/commit/3f401fe

See the detailed report from Wiz Research: Wiz Blog Post and reviewdog maintainer annoucement: reviewdog #2079

Пакеты

Наименование

reviewdog/action-setup

actions
Затронутые версииВерсия исправления

= 1

Отсутствует

EPSS

Процентиль: 94%
0.15395
Средний

8.6 High

CVSS3

Дефекты

CWE-506

Связанные уязвимости

CVSS3: 8.6
nvd
11 месяцев назад

reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be compromised, regardless of version or pinning method, are reviewdog/action-shellcheck, reviewdog/action-composite-template, reviewdog/action-staticcheck, reviewdog/action-ast-grep, and reviewdog/action-typos.

CVSS3: 8.6
fstec
11 месяцев назад

Уязвимость компонента reviewdog/action-setup платформы для совместной разработки GitHub, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 94%
0.15395
Средний

8.6 High

CVSS3

Дефекты

CWE-506