Описание
actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of actions/artifact on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using downloadArtifactInternal, downloadArtifactPublic, or streamExtractExternal for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.2 or higher. There are no known workarounds for this issue.
Уязвимые конфигурации
Конфигурация 1Версия от 2.0.0 (включая) до 2.1.7 (исключая)
cpe:2.3:a:github:actions\/artifact:*:*:*:*:*:node.js:*:*
Конфигурация 2
cpe:2.3:a:github:actions_toolkit:-:*:*:*:*:*:*:*
EPSS
Процентиль: 90%
0.0583
Низкий
7.3 High
CVSS3
7.5 High
CVSS3
Дефекты
CWE-22
CWE-22
Связанные уязвимости
CVSS3: 7.3
github
больше 1 года назад
@actions/artifact has an Arbitrary File Write via artifact extraction
EPSS
Процентиль: 90%
0.0583
Низкий
7.3 High
CVSS3
7.5 High
CVSS3
Дефекты
CWE-22
CWE-22