CVE-2024-42471
Arbitrary File Write via artifact extraction in actions/artifact
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.2 or higher. There are no known workarounds for this issue.
actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` before 2.1.7 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.7 or higher. There are no known workarounds for this issue.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2024-08-02 CVE Reserved
- 2024-09-02 CVE Published
- 2025-01-23 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/actions/toolkit/security/advisories/GHSA-6q32-hq47-5qq3 | X_refsource_confirm | |
https://github.com/actions/toolkit/pull/1666 | X_refsource_misc | |
https://snyk.io/research/zip-slip-vulnerability | X_refsource_misc |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Actions Search vendor "Actions" | Toolkit Search vendor "Actions" for product "Toolkit" | >= 2.0.0 < 2.1.2 Search vendor "Actions" for product "Toolkit" and version " >= 2.0.0 < 2.1.2" | en |
Affected
|