CVE-2025-30066
גבוהה 8.6 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)
מדדים
- CVSS 3.1
-
8.6 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N - EPSS — סבירות ניצול
- 72% (אחוזון 100) נכון ל-26/7/2026
- CWE
- CWE-506
מוצרים מושפעים
tj-actions: changed-files
קישורים
- https://blog.gitguardian.com/compromised-tj-actions/ ExploitThird Party Advisory
- https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-fi… ExploitMitigationThird Party Advisory
- https://github.com/chains-project/maven-lockfile/pull/1111 Issue Tracking
- https://github.com/espressif/arduino-esp32/issues/11127 Issue Tracking
- https://github.com/github/docs/blob/962a1c8dccb8c0f66548b324e5b921b5e4fbc3d6/c… Product
- https://github.com/modal-labs/modal-examples/issues/1100 Issue Tracking
- https://github.com/rackerlabs/genestack/pull/903 Issue Tracking
- https://github.com/tj-actions/changed-files/blob/45fb12d7a8bedb4da42342e52fe05… Product
- https://github.com/tj-actions/changed-files/issues/2463 Issue Tracking
- https://github.com/tj-actions/changed-files/issues/2464 Issue Tracking