CVE-2024-42471 is a path traversal vulnerability in actions/artifact, a GitHub Toolkit for developing GitHub Actions, affecting versions 2.x prior to 2.1.2. This flaw allows for arbitrary file writes when extracting specially crafted artifacts. With a CVSS score of 7.5 (High), it presents a significant risk due to its network-based attack vector and low attack complexity, potentially leading to high integrity impact. While not currently on the KEV catalog, an exploit (EDB-52276) exists for a related library (unzip-stream), and there is minimal community discussion or media coverage surrounding this specific CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.0.0, < 2.1.7CPE matchmatch criteria | cpe:2.3:a:github:actions\/artifact:*:*:*:*:*:node.js:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:github:actions_toolkit:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.