GHSA-6q32-hq47-5qq3
HIGHCVE-2024-42471Versions of actions/artifact before 2.1.7 are vulnerable to arbitrary file write when using downloadArtifactInternal, downloadArtifactPublic, or streamExtractExternal for extracting a specifically crafted artifact that contains path traversal filenames.
- Affected
- >= 2.0.0, < 2.1.2
- Fixed in
- 2.1.2
- Weakness
- CWE-22
- Published
- 2024-09-03
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereferencereference