Описание
act is a project which allows for local running of github actions. Prior to version 0.2.86, act unconditionally processes the deprecated ::set-env:: and ::add-path:: workflow commands, which was disabled due to environment injection risks. When a workflow step echoes untrusted data to stdout, an attacker can inject these commands to set arbitrary environment variables or modify the PATH for all subsequent steps in the job. This issue has been patched in version 0.2.86.
Ссылки
- Patch
- Product
- ExploitMitigationVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 0.2.86 (исключая)
cpe:2.3:a:nektos:act:*:*:*:*:*:*:*:*
EPSS
Процентиль: 45%
0.00619
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-74
Связанные уязвимости
github
5 месяцев назад
act: Unrestricted set-env and add-path command processing enables environment injection
EPSS
Процентиль: 45%
0.00619
Низкий
9.8 Critical
CVSS3
Дефекты
CWE-74