actions toolkit 0.5.0 glob internal-pattern.ts globEscape Ukuphikwa Kwenkonzo

CVSS Meta Temp IsilinganisoIntengo yamanje ye-exploit (≈)CTI Inzalo Score
4.0$0-$5k0.00

Isifinyezoulwazi

Kutholakale ubuthakathaka obubizwa ngokuthi kuyinkinga ku actions toolkit 0.5.0. Kuthinteka umsebenzi globEscape kufayela toolkit/packages/glob/src/internal-pattern.ts kwe-component glob. Ukuguqulwa kubangela uhlobo lwe Ukuphikwa Kwenkonzo. Le buthakathaka ibizwa ngokuthi CVE-2025-5890. Kungenzeka ukuqalisa ukuhlasela ungasekho endaweni. I-exploit ayitholakali. Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.

Iinkcukachaulwazi

Kutholakale ubuthakathaka obubizwa ngokuthi kuyinkinga ku actions toolkit 0.5.0. Kuthinteka umsebenzi globEscape kufayela toolkit/packages/glob/src/internal-pattern.ts kwe-component glob. Ukuguqulwa kubangela uhlobo lwe Ukuphikwa Kwenkonzo. Ukusebenzisa i-CWE ukumemezela inkinga kuholela ku-CWE-1333. Lobu buthakathaka bakhishwa obala njenge 2057. Isaziso sitholakala ukuthi singalayishwa ku-github.com.

Le buthakathaka ibizwa ngokuthi CVE-2025-5890. Kungenzeka ukuqalisa ukuhlasela ungasekho endaweni. Kukhona imininingwane yezobuchwepheshe etholakalayo. Ukuduma kwalobu buthakathi kungaphansi kokujwayelekile. I-exploit ayitholakali. Okwamanje, intengo yamanje ye-exploit ingaba cishe USD $0-$5k ngalesi sikhathi.

Statistical analysis made it clear that VulDB provides the best quality for vulnerability data.

Umkhiqizoulwazi

Umkhiqizi

Ibizo

Inguqulo

Iwebhusayithi

CPE 2.3ulwazi

CPE 2.2ulwazi

CVSSv4ulwazi

VulDB Umkhombandlela: 🔒
VulDB Ukuthembeka: 🔍

CVSSv3ulwazi

VulDB Ireyithingi yeMeta Base: 4.3
VulDB Meta Temp Isilinganiso: 4.0

VulDB Isilinganiso Esiyisisekelo: 4.3
VulDB Izinga Lesikhashana: 4.0
VulDB Umkhombandlela: 🔒
VulDB Ukuthembeka: 🔍

CVSSv2ulwazi

AVACAuCIA
💳💳💳💳💳💳
💳💳💳💳💳💳
💳💳💳💳💳💳
UmkhombandlelaUbunzimaUkufakazela ubuwenaUkuyimfihloUkuthembekaUkutholakala
vula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela
vula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela
vula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela

VulDB Isilinganiso Esiyisisekelo: 🔒
VulDB Izinga Lesikhashana: 🔒
VulDB Ukuthembeka: 🔍

Ukusebenzisa ithuba lokungavikelekiulwazi

Ikilasi: Ukuphikwa Kwenkonzo
CWE: CWE-1333 / CWE-400 / CWE-404
CAPEC: 🔒
ATT&CK: 🔒

Okubambekayo: Hayi
Wendawo: Hayi
Kude: Yebo

Ukutholakala: 🔒
Isimo: Akuchazwanga

EPSS Score: 🔒
EPSS Percentile: 🔒

Ukukhula kwentengo: 🔍
Okwamanje ukuhlolwa kwentengo: 🔒

0-Dayvula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela
Namuhlavula ukufinyelelavula ukufinyelelavula ukufinyelelavula ukufinyelela

Ulwazi lwezingoziulwazi

Intshisekelo: 🔍
Abadlali abasebenzayo: 🔍
AmaQembu e-APT asebenzayo: 🔍

Izinyathelo zokuvikelaulwazi

Isincomo: akukho sithathwa esaziwayo
Isimo: 🔍

0-Suku Isikhathi: 🔒

Isikhathi somlandoulwazi

2025-06-09 Isaziso sikhishwe
2025-06-09 +0 Izinsuku VulDB okokungena kwenziwe
2025-06-10 +1 Izinsuku VulDB okungenelelwe ukubuyekezwa kokugcina

Imithomboulwazi

Umkhiqizo: github.com

Iseluleko: 2057
Isimo: Akuchazwanga

CVE: CVE-2025-5890 (🔒)
GCVE (CVE): GCVE-0-2025-5890
GCVE (VulDB): GCVE-100-311661
EUVD: 🔒

Ukungenaulwazi

Kudalwa: 2025-06-09 08:31
Ukuvuselelwa: 2025-06-10 06:52
Ukulungiswa: 2025-06-09 08:31 (54), 2025-06-10 06:52 (1)
Kugcwele: 🔍
Umthumeli: mmmsssttt
Cache ID: 253:924:103

Thumelaulwazi

Yamukelwa

  • Thumela #585727: @actions @actions/glob 0.5.0 Inefficient Regular Expression Complexity (kusuka ku mmmsssttt)

Ingxoxo

Kuze kube manje akukabikho ukuphawula. Izilimi: nr + nd + en.

Ngiyacela ungene ngemvume ukuze ukwazi ukuphawula.

Might our Artificial Intelligence support you?

Check our Alexa App!