CVE-2024-42482 describes a command injection vulnerability in the fish-shop/syntax-check GitHub Action, affecting versions prior to v1.6.12 and v2.0.0. This flaw allows arbitrary command execution due to improper neutralization of delimiters in the 'pattern' input, potentially leading to sensitive data exposure or exfiltration from the workflow runner. With a CVSS score of 6.5 (Medium), the vulnerability is network-exploitable with low attack complexity and no user interaction required, though its impact is limited to confidentiality and integrity. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.6.12CPE matchmatch criteria | cpe:2.3:a:fish-shop:syntax-check:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.