Логотип exploitDog
bind:CVE-2025-30154
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-30154

Количество 3

Количество 3

nvd логотип

CVE-2025-30154

11 месяцев назад

reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be compromised, regardless of version or pinning method, are reviewdog/action-shellcheck, reviewdog/action-composite-template, reviewdog/action-staticcheck, reviewdog/action-ast-grep, and reviewdog/action-typos.

CVSS3: 8.6
EPSS: Средний
github логотип

GHSA-qmg3-hpqr-gqvc

11 месяцев назад

Multiple Reviewdog actions were compromised during a specific time period

CVSS3: 8.6
EPSS: Средний
fstec логотип

BDU:2025-03223

11 месяцев назад

Уязвимость компонента reviewdog/action-setup платформы для совместной разработки GitHub, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 8.6
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-30154

reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be compromised, regardless of version or pinning method, are reviewdog/action-shellcheck, reviewdog/action-composite-template, reviewdog/action-staticcheck, reviewdog/action-ast-grep, and reviewdog/action-typos.

CVSS3: 8.6
15%
Средний
11 месяцев назад
github логотип
GHSA-qmg3-hpqr-gqvc

Multiple Reviewdog actions were compromised during a specific time period

CVSS3: 8.6
15%
Средний
11 месяцев назад
fstec логотип
BDU:2025-03223

Уязвимость компонента reviewdog/action-setup платформы для совместной разработки GitHub, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 8.6
15%
Средний
11 месяцев назад

Уязвимостей на страницу