46 이전의 tj-actions 변경 파일을 사용하면 원격 공격자가 작업 로그를 읽어 비밀을 발견할 수 있습니다. (v1부터 v45.0.7까지의 태그는 악성 updateFeatures 코드가 포함된 커밋 0e58ed8을 가리키도록 위협 행위자에 의해 수정되었기 때문에 2025-03-14 및 2025-03-15에 영향을 받았습니다.)
왜 이 VPI인가 (설명가능 · 실험적)
VPI 산정 기준
| 영향도 | 86.00 |
| 악용 신호(KEV 등재) | ×1.50 |
| VPI | 100.00 |
VPI 공식 vpi-v1 기준
필수 조치
Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
46 이전의 tj-actions 변경 파일을 사용하면 원격 공격자가 작업 로그를 읽어 비밀을 발견할 수 있습니다. (v1부터 v45.0.7까지의 태그는 악성 updateFeatures 코드가 포함된 커밋 0e58ed8을 가리키도록 위협 행위자에 의해 수정되었기 때문에 2025-03-14 및 2025-03-15에 영향을 받았습니다.)