HIGH
Arbitrary File Write via artifact extraction in actions/artifact
Published Sep 2, 2024
8.6
HIGHCVSS 4.0
EPSS 3.22%
Description
actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that contains path traversal filenames. Users are advised to upgrade to version 2.1.2 or higher. There are no known workarounds for this issue.
Affected products
-
- Version >= 2.0.0, < 2.1.2StatusaffectedConstraints-
- Version
Configuration 1
- ≥ 2.0.0 · < 2.1.7
Configuration 2
- n/a
No data.
No Red Hat product state for this CVE.
@actions/artifact
npm
Introduced 2.0.0 Fixed 2.1.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @actions/artifact | 2.0.0 | 2.1.2 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-2737 Advisory
- https://github.com/actions/download-artifact/blob/v3/package.json#L31
- https://github.com/actions/toolkit/commit/29885a805ef3e95a9862dcaa8431c30981960017
- https://github.com/actions/toolkit/pull/1602
- https://github.com/actions/toolkit/pull/1666 x_refsource_MISC
- https://github.com/actions/toolkit/pull/1724
- https://github.com/actions/toolkit/security/advisories/GHSA-6q32-hq47-5qq3 x_refsource_CONFIRMVendor Advisory
- https://github.com/advisories/GHSA-6q32-hq47-5qq3 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-42471
- https://snyk.io/research/zip-slip-vulnerability x_refsource_MISCNot Applicable
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Sep 2, 2024
Updated Aug 27, 2025
Reserved Aug 2, 2024
Link CVE-2024-42471
CISA Vulnrichment
Updated Jan 23, 2025
ENISA EUVD
EUVD-2024-2737 GHSA-6Q32-HQ47-5QQ3 Assigner GitHub_M
Published Sep 2, 2024
Updated Aug 27, 2025
Exploited since n/a
Link EUVD-2024-2737