Beveiligingsadvies

CVE-2023-2181

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2023-05-12 00:00:00
Laatst bijgewerkt 2025-01-24 15:47:03
Toegewezen door GitLab
CVSS-score 6.3
Status PUBLISHED

Beschrijving

An issue has been discovered in GitLab affecting all versions before 15.9.8, 15.10.0 before 15.10.7, and 15.11.0 before 15.11.3. A malicious developer could use a git feature called refs/replace to smuggle content into a merge request which would not be visible during review in the UI.