CVE-2024-42471
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD
Description
actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.2 or higher. There are no known workarounds for this issue.
Affected (2)
Products: Github: Actions/artifact, Actions Toolkit
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.0.0 to 2.1.7 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
References (3)
Source: security-advisories@github.com
Source: security-advisories@github.com
Vendor Advisory
Timeline
No history available yet.