Описание
A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects the function globEscape of the file toolkit/packages/glob/src/internal-pattern.ts of the component glob. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotely.
EPSS
Процентиль: 12%
0.00041
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-400
Связанные уязвимости
CVSS3: 4.3
github
10 дней назад
A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects the function globEscape of the file toolkit/packages/glob/src/internal-pattern.ts of the component glob. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotely.
EPSS
Процентиль: 12%
0.00041
Низкий
4.3 Medium
CVSS3
4 Medium
CVSS2
Дефекты
CWE-400