CVE-2025-30066

HIGH(8.6)KEVErhöhtes Risiko

tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability

Beschreibung

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)

KEV-Informationen

Hersteller
tj-actions
Produkt
changed-files GitHub Action
Hinzugefügt am
18. März 2025
Fälligkeitsdatum
8. April 2025
Erforderliche Maßnahme
Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVSS-Score

Vektorstring
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:NIm Rechner öffnen
Angriffsvektor
NETWORK
Angriffskomplexität
LOW
Erforderliche Privilegien
NONE
Benutzerinteraktion
NONE
Scope
CHANGED
Vertraulichkeitsauswirkung
HIGH
Integritätsauswirkung
NONE
Verfügbarkeitsauswirkung
NONE
Ausnutzbarkeitsscore
3.9
Auswirkungsscore
4.0

CWEs

Betroffene Produkte

HerstellerProduktVersion
tj-actionschanged-files<= 45.0.7

Mehrere CVSS-Bewertungen

Quelle: [email protected](Secondary)
8.6
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Quelle: [email protected](Primary)
8.6
HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Referenzen

CVSS-Score

8.6
HIGH(8.6)

EPSS-Score

EPSS-Score41.01%
EPSS-Perzentil98.5%

Daten

Veröffentlicht15. März 2025
Zuletzt geändert17. Juni 2026
StatusAnalyzed
CVSS-Versionv3.1

Hilfe beim Schwachstellenmanagement?

Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.