Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork36.2k
Actions expression injection in `helpers/version/action.yml`
Low
Package
home-assistant/actions/helpers/version (GitHub Actions)
Affected versions
< September 5, 2023
Patched versions
September 5, 2023
Description
TheGitHub Security Lab team has identified a potential security vulnerability inHome Assistant's GitHub Actions.
Summary
Thehome-assistant/actionshelpers/version workflow is vulnerable to a command injection in GitHub Actions, allowing an attacker to leak secrets and alter the repository using the workflow potentially.
Credit
This issue was discovered and reported by GHSL team members@jorgectf (Jorge) and@p- (Peter Stöckli).
GitHub Security Lab (GHSL) Vulnerability Report:GHSL-2023-179