{"id":"GHSA-xj87-mqvh-88w2","summary":"fish-shop/syntax-check Improper Neutralization of Delimiters","details":"### Impact\n\nImproper neutralisation of delimiters in the `pattern` input (specifically the command separator `;` and command substitution characters `(` and `)`) mean that arbitrary command injection is possible by modification of the input value used in a workflow. This has the potential for exposure or exfiltration of sensitive information from the workflow runner, such as might be achieved by sending environment variables to an external entity.\n\n### Patches\n\nAs of this writing, the issue has been patched for versions in the `v1.x.x` release series in release `v1.6.12` (also tagged as `v1.6` and `v1`). The latest available release `v2.0.0` also includes a corresponding patch (also tagged as `v2.0` and `v2`).\n\nUsers should upgrade to at least the patched version `v1.6.12` or preferably the latest available version `v2.0.0`. Workflows that use the action ref `v1` will automatically receive the patched version `v1.6.12` in future workflow runs.\n\nPatch summary:\n\n| Release series | Patched tags    | Patched commit hashes |\n|----------------|-------------------------|-------------|\n| `1.x.x`        | `v1.6.12`, `v1.6`, `v1` | `91e6817c48ad475542fe4e78139029b036a53b03`    |\n| `2.x.x`        | `v2.0.0`, `v2.0`, `v2`  | `c2cb11395e21119ff8d6e7ea050430ee7d6f49ca`    |\n\n### Workarounds\n\nIs it recommended that users update to the patched version `v1.6.12` or the latest release version `v2.0.0`, however remediation may be possible through careful control of workflows and the `pattern` input value used by this action.\n\n### References\n\n- [CWE-140: Improper Neutralization of Delimiters](https://cwe.mitre.org/data/definitions/140.html)\n- [CAPEC-15: Command Delimiters](https://capec.mitre.org/data/definitions/15.html)\n","aliases":["CVE-2024-42482"],"modified":"2024-08-12T19:16:59Z","published":"2024-08-12T18:25:20Z","database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2024-08-12T18:25:20Z","nvd_published_at":"2024-08-12T16:15:16Z","cwe_ids":["CWE-140"]},"references":[{"type":"WEB","url":"https://github.com/fish-shop/syntax-check/security/advisories/GHSA-xj87-mqvh-88w2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-42482"},{"type":"WEB","url":"https://github.com/fish-shop/syntax-check/commit/91e6817c48ad475542fe4e78139029b036a53b03"},{"type":"WEB","url":"https://github.com/fish-shop/syntax-check/commit/c2cb11395e21119ff8d6e7ea050430ee7d6f49ca"},{"type":"PACKAGE","url":"https://github.com/fish-shop/syntax-check"}],"affected":[{"package":{"name":"fish-shop/syntax-check","ecosystem":"GitHub Actions"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6.12"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/08/GHSA-xj87-mqvh-88w2/GHSA-xj87-mqvh-88w2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N"}]}