actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` before 2.1.7 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.7 or higher. There are no known workarounds for this issue.
References
Link | Resource |
---|---|
https://github.com/actions/toolkit/pull/1724 | Patch |
https://github.com/actions/toolkit/security/advisories/GHSA-6q32-hq47-5qq3 | Vendor Advisory |
https://snyk.io/research/zip-slip-vulnerability | Not Applicable |
Configurations
History
16 Sep 2024, 16:18
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/actions/toolkit/pull/1724 - Patch | |
References | () https://github.com/actions/toolkit/security/advisories/GHSA-6q32-hq47-5qq3 - Vendor Advisory | |
References | () https://snyk.io/research/zip-slip-vulnerability - Not Applicable | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
First Time |
Github actions Toolkit
Github Github actions\/artifact |
|
CPE | cpe:2.3:a:github:actions\/artifact:*:*:*:*:*:node.js:*:* cpe:2.3:a:github:actions_toolkit:-:*:*:*:*:*:*:* |
03 Sep 2024, 12:59
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
02 Sep 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-02 18:15
Updated : 2024-09-16 16:18
NVD link : CVE-2024-42471
Mitre link : CVE-2024-42471
CVE.ORG link : CVE-2024-42471
JSON object : View
Products Affected
github
- actions_toolkit
- actions\/artifact
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')