Vulnerabilidades em actions
6 resultadosAnálise Vexday
O fornecedor actions possui 6 vulnerabilidades registradas na base Vexday, nenhuma delas sob exploração ativa conhecida ou com severidade crítica. Não há descobertas recentes (últimos 90 dias), indicando um panorama de risco estável e de baixa prioridade operacional, com a fraqueza dominante concentrada em CWE-1333.
CVE-2024-42471HIGHArbitrary File Write via artifact extraction in actions/artifactEPSS 3.2%CVE-2020-11021MEDIUMHTTP request which redirect to another hostname do not strip authorization header in Actions Http-ClientEPSS 1.7%CVE-2022-39321HIGHGitHub Actions Runner vulnerable to Docker Command EscapingEPSS 1.6%CVE-2020-15228LOWEnvironment Variable Injection in GitHub ActionsEPSS 1.5%CVE-2022-35954MEDIUMDelimiter injection vulnerability in @actions/core exportVariableEPSS 0.7%CVE-2025-5890MEDIUMactions toolkit glob internal-pattern.ts globEscape redosEPSS 0.4%