GHSA-7r3h-m5j6-3q42

    Dashboard / Vulnerabilities / GHSA-7r3h-m5j6-3q42

    GHSA-7r3h-m5j6-3q42

    Published: 18 Aug 2022Last Modified: 8 Nov 2023

    Summary: @actions/core has Delimiter Injection Vulnerability in exportVariable

    Details: ## Impact The `core.exportVariable` function uses a well known delimiter that attackers can use to break out of that specific variable and assign values to other arbitrary variables. Workflows that write untrusted values to the `GITHUB_ENV` file may cause the path or other environment variables to be modified without the intention of the workflow or action author. ## Patches Users should upgrade to `@actions/core v1.9.1`. ## Workarounds If you are unable to upgrade the `@actions/core` package, you can modify your action to ensure that any user input does not contain the delimiter `_GitHubActionsFileCommandDelimeter_` before calling `core.exportVariable`. ## References [More information about setting-an-environment-variable in workflows](https://docs.github.com/en/actions/using-workflows/workflow-commands-for-github-actions#setting-an-environment-variable) If you have any questions or comments about this advisory: * Open an issue in [`actions/toolkit`](https://github.com/actions/toolkit/issues)

    Affected packages

    Package

    Name: @actions/core

    Purl: pkg:npm/%40actions/core

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.9.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-7r3h-m5j6-3q42 | CVE-DB