← Back

CVE-2024-42471

nvd nist
Published: Sep 2, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.2 or higher. There are no known workarounds for this issue.

Affected (2)

2 products
Actions/artifact
Actions Toolkit
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
From 2.0.0 to 2.1.7
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (3)

Source: security-advisories@github.com
Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
Not Applicable

Timeline

No history available yet.