Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-30853

Опубликовано: 28 апр. 2023
Источник: nvd
CVSS3: 7.6
CVSS3: 6.5
EPSS Низкий

Описание

Gradle Build Action allows users to execute a Gradle Build in their GitHub Actions workflow. A vulnerability impacts GitHub workflows using the Gradle Build Action prior to version 2.4.2 that have executed the Gradle Build Tool with the configuration cache enabled, potentially exposing secrets configured for the repository.

Secrets configured for GitHub Actions are normally passed to the Gradle Build Tool via environment variables. Due to the way that the Gradle Build Tool records these environment variables, they may be persisted into an entry in the GitHub Actions cache. This data stored in the GitHub Actions cache can be read by a GitHub Actions workflow running in an untrusted context, such as that running for a Pull Request submitted by a developer via a repository fork.

This vulnerability was discovered internally through code review, and we have not seen any evidence of it being exploited in the wild. However, in addition to upgrading the Gradle Build Action, affected users sh

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gradle:build_action:*:*:*:*:*:*:*:*
Версия до 2.4.2 (исключая)

EPSS

Процентиль: 41%
0.00187
Низкий

7.6 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-312

Связанные уязвимости

CVSS3: 7.6
github
почти 3 года назад

Data written to GitHub Actions Cache may expose secrets

EPSS

Процентиль: 41%
0.00187
Низкий

7.6 High

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-200
CWE-312