Описание
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.
Ссылки
- Third Party Advisory
- Broken Link
- Permissions Required
- Third Party Advisory
- Broken Link
- Permissions Required
Уязвимые конфигурации
Одно из
EPSS
6.5 Medium
CVSS3
5 Medium
CVSS2
Дефекты
Связанные уязвимости
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.
An issue has been discovered affecting GitLab versions prior to 14.4.5 ...
An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.
EPSS
6.5 Medium
CVSS3
5 Medium
CVSS2