What is CVE-2024-58354?
This CVE describes a repository takeover vulnerability in cal.com (now cal.diy) GitHub Actions. The `pr.yml` workflow uses `pull_request_target` trigger with default write permissions, passing them to `check-types.yml`, which creates a security gap. The GitHub Actions configuration should be immediately reviewed and `write` permissions restricted to prevent exploitation.
Azərbaycanca: Bu CVE cal.com (hazırda cal.diy adlanır) GitHub Actions iş axınında depo ələ keçirmə zəifliyini təsvir edir. `pull_request_target` trigger-i ilə yazılış icazələrinin `check-types.yml`-ə ötürülməsi təhlükəsizlik boşluğu yaradır. İstismarın qarşısını almaq üçün GitHub Actions konfiqurasiyası dərhal nəzərdən keçirilməli və `write` icazələri məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-1188
FAQ2
In which platform's workflow was CVE-2024-58354 detected?
CVE-2024-58354 is a repository takeover vulnerability found in the GitHub Actions workflow of cal.com (now known as cal.diy).
What is the primary measure to prevent exploitation of this vulnerability?
To prevent exploitation, the GitHub Actions configuration should be immediately reviewed and `write` permissions restricted.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.