VDB

CVE-2020-15228

CVE-2020-15228 PUBLISHED CVSS 3.5 LOW

Environment Variable Injection in GitHub Actions

EPSS 0.61% · 70.1th percentile

Risk Scores

CVSS 3.1
3.5
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N
EPSS Score
0.61%
70.1th percentile

Affected Products

VendorProductVersions
actionscore0, 0, 0
toolkit_projecttoolkit0, 0, 0
Azurefunctions
actionstoolkit< 1.2.6, < 1.2.6, < 1.2.6
Salesforceflow
Oracle Cloudfunctions

Timeline

  • Oct 1, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Nov 18, 2021 CVE Updated
  • Dec 27, 2021 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
  • Nov 6, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›