Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-47179

Опубликовано: 26 сент. 2024
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

RSSHub is an RSS network. Prior to commit 64e00e7, RSSHub's docker-test-cont.yml workflow is vulnerable to Artifact Poisoning, which could have lead to a full repository takeover. Downstream users of RSSHub are not vulnerable to this issue, and commit 64e00e7 fixed the underlying issue and made the repository no longer vulnerable. The docker-test-cont.yml workflow gets triggered when the PR - Docker build test workflow completes successfully. It then collects some information about the Pull Request that triggered the triggering workflow and set some labels depending on the PR body and sender. If the PR also contains a routes markdown block, it will set the TEST_CONTINUE environment variable to true. The workflow then downloads and extracts an artifact uploaded by the triggering workflow which is expected to contain a single rsshub.tar.zst file. However, prior to commit 64e00e7, it did not validate and the contents were extracted in the root of the workspace overriding any

EPSS

Процентиль: 48%
0.00254
Низкий

8.8 High

CVSS3

Дефекты

CWE-20

EPSS

Процентиль: 48%
0.00254
Низкий

8.8 High

CVSS3

Дефекты

CWE-20