Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-51664

Опубликовано: 27 дек. 2023
Источник: nvd
CVSS3: 7.3
CVSS3: 9.8
EPSS Низкий

Описание

tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the tj-actions/changed-files workflow allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. This issue may lead to arbitrary command execution in the GitHub Runner. This vulnerability has been addressed in version 41.0.0. Users are advised to upgrade.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:tj-actions:changed-files:*:*:*:*:*:*:*:*
Версия до 41.0.0 (исключая)

EPSS

Процентиль: 71%
0.00673
Низкий

7.3 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-74
CWE-77

Связанные уязвимости

CVSS3: 7.3
github
около 2 лет назад

tj-actions/changed-files has Potential Actions command injection in output filenames (GHSL-2023-271)

EPSS

Процентиль: 71%
0.00673
Низкий

7.3 High

CVSS3

9.8 Critical

CVSS3

Дефекты

CWE-74
CWE-77