A vulnerability classified as problematic has been found in actions toolkit 0.5.0. This affects the function globEscape of the file toolkit/packages/glob/src/internal-pattern.ts of the component glob. The manipulation leads to inefficient regular expression complexity. It is possible to initiate the attack remotely.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://vuldb.com/?id.311661 | technical description vdb entry |
https://vuldb.com/?ctiid.311661 | permissions required signature |
https://vuldb.com/?submit.585727 | third party advisory |
https://github.com/actions/toolkit/pull/2057 | issue tracking |