Описание
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended path prefix and access arbitrary GitLab API resources using the operator's personal access token.
Ссылки
EPSS
Процентиль: 31%
0.0038
Низкий
8.6 High
CVSS3
Дефекты
CWE-73
Связанные уязвимости
CVSS3: 8.6
github
около 1 месяца назад
mcp-gitlab contains a path traversal vulnerability in the job_id parameter of build/index.js that allows attackers to redirect GitLab API requests to arbitrary endpoints. Attackers can supply crafted job_id values like ../../../user to escape the intended path prefix and access arbitrary GitLab API resources using the operator's personal access token.
EPSS
Процентиль: 31%
0.0038
Низкий
8.6 High
CVSS3
Дефекты
CWE-73