gitlab-org/gitaly

gitlab-org/gitaly

Releases1.22K
Frequency2 days 20 hours
Last Release
Stars434
Gitaly is a Git RPC service for handling all the git calls made by GitLab

CVE History

CVEPublishedCVSS v3CVSS v2
6.5 MEDIUM

An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code execution.

6.5 MEDIUM5 MEDIUM

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.

2.5 LOW2.1 LOW

When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.