-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability documentation explicitly references a missing permission check in GitLabConnectionConfig#doTestConnection. The commit diff shows this method was modified to add @RequirePOST and ADMINISTER permission checks, confirming it was the vulnerable entry point. The method's purpose (testing connections with arbitrary credentials/URLs) aligns perfectly with the described attack vector.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:gitlab-plugin | maven | <= 1.5.11 | 1.5.12 |
Ongoing coverage of React2Shell