Movatterモバイル変換


[0]ホーム

URL:


Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up
Appearance settings

Actions expression injection in `helpers/version/action.yml`

Low
frenck publishedGHSA-jff5-5j3g-vhqcOct 19, 2023

Package

actionshome-assistant/actions/helpers/version (GitHub Actions)

Affected versions

< September 5, 2023

Patched versions

September 5, 2023

Description

TheGitHub Security Lab team has identified a potential security vulnerability inHome Assistant's GitHub Actions.

Summary

Thehome-assistant/actionshelpers/version workflow is vulnerable to a command injection in GitHub Actions, allowing an attacker to leak secrets and alter the repository using the workflow potentially.

Credit

This issue was discovered and reported by GHSL team members@jorgectf (Jorge) and@p- (Peter Stöckli).

GitHub Security Lab (GHSL) Vulnerability Report:GHSL-2023-179

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs

Credits


[8]ページ先頭

©2009-2025 Movatter.jp