GHSA-7f32-hm4h-w77q – rlespinasse/github-slug-action
Package
Manager: github_actions
Name: rlespinasse/github-slug-action
Vulnerable Version: >=0 <1.1.1 || >=2.0.0 <2.1.1
Severity
Level: Medium
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N/E:H/RL:U/RC:C
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N
EPSS: N/A pctlN/A
Details
github-slug-action use of `set-env` Runner commands which are processed via stdout ### Impact This GitHub Action use `set-env` runner commands which are processed via stdout related to GHSA-mfwh-5m23-j46w ### Patches The following versions use the recommended [Environment File Syntax](https://github.com/actions/toolkit/blob/main/docs/commands.md#environment-files). - 2.1.1 - 1.1.1 ### Workarounds None, it is strongly suggested that you upgrade as soon as possible. ### For more information If you have any questions or comments about this advisory: * Open an issue in [rlespinasse/github-slug-action](https://github.com/rlespinasse/github-slug-action)
Metadata
Created: 2024-02-03T00:22:22Z
Modified: 2024-04-22T18:47:56Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-7f32-hm4h-w77q/GHSA-7f32-hm4h-w77q.json
CWE IDs: []
Alternative ID: N/A
Finding: F422
Auto approve: 1