GMS-2022-7315: code injection in phpxmlrpc/phpxmlrpc
code injection in Wrapper::buildClientWrapperCode
via manipulation of the $client
argument. It was possible to force the client to access local files or connect to undesired urls instead of the intended target server’s url.
References
Detect and mitigate GMS-2022-7315 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →