actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.2 or higher. There are no known workarounds for this issue.
References
Link | Resource |
---|---|
https://github.com/actions/toolkit/pull/1666 | |
https://github.com/actions/toolkit/security/advisories/GHSA-6q32-hq47-5qq3 | Vendor Advisory |
https://snyk.io/research/zip-slip-vulnerability | Not Applicable |
Configurations
History
22 Jan 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
Summary | (en) actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.2 or higher. There are no known workarounds for this issue. |
22 Jan 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
Summary | (en) actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.7 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.7 or higher. There are no known workarounds for this issue. |
Information
Published : 2024-09-02 18:15
Updated : 2025-01-23 22:15
NVD link : CVE-2024-42471
Mitre link : CVE-2024-42471
CVE.ORG link : CVE-2024-42471
JSON object : View
Products Affected
github
- actions_toolkit
- actions\/artifact
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')