GHSA-7f32-hm4h-w77q

Suggest an improvement
Source
https://github.com/advisories/GHSA-7f32-hm4h-w77q
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/02/GHSA-7f32-hm4h-w77q/GHSA-7f32-hm4h-w77q.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7f32-hm4h-w77q
Published
2024-02-03T00:22:22Z
Modified
2024-04-22T18:47:56Z
Summary
github-slug-action use of `set-env` Runner commands which are processed via stdout
Details

Impact

This GitHub Action use set-env runner commands which are processed via stdout related to GHSA-mfwh-5m23-j46w

Patches

The following versions use the recommended Environment File Syntax.

  • 2.1.1
  • 1.1.1

Workarounds

None, it is strongly suggested that you upgrade as soon as possible.

For more information

If you have any questions or comments about this advisory: * Open an issue in rlespinasse/github-slug-action

Database specific
{
    "nvd_published_at": null,
    "cwe_ids": [],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-02-03T00:22:22Z"
}
References

Affected packages

GitHub Actions / rlespinasse/github-slug-action

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.1.1

Database specific

{
    "last_known_affected_version_range": "<= 1.1.0"
}

GitHub Actions / rlespinasse/github-slug-action

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.0.0
Fixed
2.1.1

Database specific

{
    "last_known_affected_version_range": "<= 2.1.0"
}