fish-shop/syntax-check is a GitHub action for syntax checking fish shell files. Improper neutralization of delimiters in the `pattern` input (specifically the command separator `;` and command substitution characters `(` and `)`) mean that arbitrary command injection is possible by modification of the input value used in a workflow. This has the potential for exposure or exfiltration of sensitive information from the workflow runner, such as might be achieved by sending environment variables to an external entity. It is recommended that users update to the patched version `v1.6.12` or the latest release version `v2.0.0`, however remediation may be possible through careful control of workflows and the `pattern` input value used by this action.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Sep 2024 12:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Fish-shop
Fish-shop syntax-check |
|
Weaknesses | NVD-CWE-Other | |
CPEs | cpe:2.3:a:fish-shop:syntax-check:*:*:*:*:*:*:*:* | |
Vendors & Products |
Fish-shop
Fish-shop syntax-check |
Tue, 13 Aug 2024 18:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 12 Aug 2024 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | fish-shop/syntax-check is a GitHub action for syntax checking fish shell files. Improper neutralization of delimiters in the `pattern` input (specifically the command separator `;` and command substitution characters `(` and `)`) mean that arbitrary command injection is possible by modification of the input value used in a workflow. This has the potential for exposure or exfiltration of sensitive information from the workflow runner, such as might be achieved by sending environment variables to an external entity. It is recommended that users update to the patched version `v1.6.12` or the latest release version `v2.0.0`, however remediation may be possible through careful control of workflows and the `pattern` input value used by this action. | |
Title | fish-shop/syntax-check Improper Neutralization of Delimiters | |
Weaknesses | CWE-140 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-08-12T15:35:57.157Z
Updated: 2024-08-13T17:48:18.971Z
Reserved: 2024-08-02T14:13:04.617Z
Link: CVE-2024-42482
Vulnrichment
Updated: 2024-08-13T17:48:14.752Z
NVD
Status : Analyzed
Published: 2024-08-12T16:15:16.213
Modified: 2024-09-17T12:20:58.323
Link: CVE-2024-42482
Redhat
No data.