Описание
A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects the function globEscape of the file toolkit/packages/glob/src/internal-pattern.ts of the component glob. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotely.
EPSS
Процентиль: 27%
0.00347
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-400
Связанные уязвимости
CVSS3: 4.3
github
около 1 года назад
A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects the function globEscape of the file toolkit/packages/glob/src/internal-pattern.ts of the component glob. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotely.
EPSS
Процентиль: 27%
0.00347
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-400