Acme.Sh Project

Acme.Sh

2 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.03%
  • Published 04.04.2025 00:00:00
  • Last modified 07.04.2025 14:18:15

The Docker image from acme.sh before 40b6db6 is based on a .github/workflows/dockerhub.yml file that lacks "persist-credentials: false" for actions/checkout.

  • EPSS 0.2%
  • Published 13.07.2023 03:15:09
  • Last modified 21.11.2024 08:13:03

acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.