See how github compares to other vendors in security performance
Impact
Versions of actions/artifact before 2.1.7 are vulnerable to arbitrary file write when using downloadArtifactInternal, downloadArtifactPublic, or streamExtractExternal for extracting a specifically crafted artifact that contains path traversal filenames.
Patches
Upgrade to version 2.1.7 or higher.
References
- https://snyk.io/research/zip-slip-vulnerability - https://github.com/actions/toolkit/pull/1724
CVE
CVE-2024-42471
Credits
Justin Taft from Google