Fiche vulnérabilité
CVE-2025-30066 : faille exploitée tj-actions changed-files (CVSS 8.6)
Description
tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)
En bref
- Sévérité
- Élevée (CVSS 8.6)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
- Exploitation active
- Oui, inscrite au catalogue CISA KEV
- Publication
- 15 mars 2025
- Dernière mise à jour
- 24 sept. 2026
Produits concernés
- tj-actions changed-files
Correctif et mesures
Apply mitigations as set forth in the CISA instructions linked below. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Références
- Fiche CVE-2025-30066 sur le NVD (NIST)
- blog.gitguardian.com/compromised-tj-actions/
- github.com/chains-project/maven-lockfile/pull/1111
- github.com/espressif/arduino-esp32/issues/11127
- github.com/github/docs/blob/962a1c8dccb8c0f66548b324e5b92…
- github.com/modal-labs/modal-examples/issues/1100
- github.com/rackerlabs/genestack/pull/903
- github.com/tj…
- github.com/tj-actions/changed-files/issues/2463
- github.com/tj-actions/changed-files/issues/2464
- github.com/tj-actions/changed-files/issues/2477
- news.ycombinator.com/item
- news.ycombinator.com/item
- semgrep.dev/blog/2025/popular…
- sysdig.com/blog/detecting…
- web.archive.org/web/20250315060250/https…