Executive Summary

Informations
Name CVE-2025-30066 First vendor Publication 2025-03-15
Vendor Cve Last vendor Modification 2025-03-29

Security-Database Scoring CVSS v3

Cvss vector : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Overall CVSS Score 8.6
Base Score 8.6 Environmental Score 8.6
impact SubScore 4 Temporal Score 8.6
Exploitabality Sub Score 3.9
 
Attack Vector Network Attack Complexity Low
Privileges Required None User Interaction None
Scope Changed Confidentiality Impact High
Integrity Impact None Availability Impact None
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector :
Cvss Base Score N/A Attack Range N/A
Cvss Impact Score N/A Attack Complexity N/A
Cvss Expoit Score N/A Authentication N/A
Calculate full CVSS 2.0 Vectors scores

Detail

tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.)

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-30066

CPE : Common Platform Enumeration

TypeDescriptionCount
Application 1

Sources (Detail)

https://blog.gitguardian.com/compromised-tj-actions/
https://github.com/chains-project/maven-lockfile/pull/1111
https://github.com/espressif/arduino-esp32/issues/11127
https://github.com/github/docs/blob/962a1c8dccb8c0f66548b324e5b921b5e4fbc3d6/...
https://github.com/modal-labs/modal-examples/issues/1100
https://github.com/rackerlabs/genestack/pull/903
https://github.com/tj-actions/changed-files/blob/45fb12d7a8bedb4da42342e52fe0...
https://github.com/tj-actions/changed-files/issues/2463
https://github.com/tj-actions/changed-files/issues/2464
https://github.com/tj-actions/changed-files/issues/2477
https://news.ycombinator.com/item?id=43367987
https://news.ycombinator.com/item?id=43368870
https://semgrep.dev/blog/2025/popular-github-action-tj-actionschanged-files-i...
https://sysdig.com/blog/detecting-and-mitigating-the-tj-actions-changed-files...
https://web.archive.org/web/20250315060250/https://github.com/tj-actions/chan...
https://www.cisa.gov/news-events/alerts/2025/03/18/supply-chain-compromise-th...
https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-f...
https://www.stream.security/post/github-action-supply-chain-attack-exposes-se...
https://www.sweet.security/blog/cve-2025-30066-tj-actions-supply-chain-attack
https://www.wiz.io/blog/github-action-tj-actions-changed-files-supply-chain-a...
Source Url

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
Date Informations
2025-03-29 09:20:36
  • Multiple Updates
2025-03-20 03:17:20
  • Multiple Updates
2025-03-20 03:17:18
  • Multiple Updates
2025-03-20 00:20:32
  • Multiple Updates
2025-03-19 09:20:32
  • Multiple Updates
2025-03-19 05:20:32
  • Multiple Updates
2025-03-19 00:20:29
  • Multiple Updates
2025-03-17 05:20:31
  • Multiple Updates
2025-03-17 03:18:44
  • Multiple Updates
2025-03-17 03:18:43
  • Multiple Updates
2025-03-16 21:20:37
  • Multiple Updates
2025-03-16 13:20:34
  • Multiple Updates
2025-03-16 09:20:31
  • Multiple Updates
2025-03-16 03:23:12
  • Multiple Updates
2025-03-15 17:20:33
  • Multiple Updates
2025-03-15 13:20:31
  • First insertion