Loading HuntDB...

GHSA-r77r-m2hf-8495

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab is configured in a way that it doesn't ignore replacement references with git sub-commands, allowing a malicious user to spoof the contents of their commits in the UI.

Related CVEs

Key Information

GHSA ID
GHSA-r77r-m2hf-8495
Published
January 19, 2022 12:01 AM
Last Modified
January 26, 2022 12:03 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: June 17, 2025 6:25 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.