GO-2023-1504
Dashboard / Vulnerabilities / GO-2023-1504
GO-2023-1504
Summary: act vulnerable to arbitrary file upload in artifact server in github.com/nektos/act
Details: act vulnerable to arbitrary file upload in artifact server in github.com/nektos/act
References: https://github.com/nektos/act/security/advisories/GHSA-pc99-qmg4-rcff, https://nvd.nist.gov/vuln/detail/CVE-2023-22726, https://securitylab.github.com/advisories/GHSL-2023-004_act, https://github.com/nektos/act/commit/63ae215071f94569d910964bdee866d91d6e3a10, https://github.com/nektos/act/issues/1553, https://github.com/nektos/act/blob/master/pkg/artifacts/server.go#L65, https://github.com/nektos/act/blob/v0.2.35/pkg/artifacts/server.go#L245, https://github.com/nektos/act/blob/v0.2.35/pkg/artifacts/server.go#LL103C2-L103C2, https://github.com/nektos/act/releases/tag/v0.2.40
Affected packages
Package
Name: github.com/nektos/act
Purl: pkg:golang/github.com/nektos/act
Affected ranges
Type: SEMVER
Events:
