Vulnerabilities (CVE)

Filtered by vendor Tj-actions
Filtered by product Verify-changed-files
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-52137 1 Tj-actions 1 Verify-changed-files 2024-11-21 N/A 7.7 HIGH
The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. The [`verify-changed-files`](https://github.com/tj-actions/verify-changed-files) workflow returns the list of files changed within a workflow execution. This could potentially allow filenames that contain special characters such as `;` which can be used by an attacker to t ...

Show More