
Find real vulnerabilities before they ship
When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.
Base Score
3.2| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| gitaly(RubyGems) | 1.79.0 | 13.3.9 | N/A |
| gitaly(RubyGems) | 13.4 | 13.4.5 | N/A |
| gitaly(RubyGems) | 13.5 | 13.5.2 | N/A |
| Base Score | 3.2 |
|---|---|
| Vector String | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N |
| Base Severity | Low |
| Version | 3.1 |
| Attack Vector (AV) | LOCAL |