CVE-2014-8350: Secure mode bypass
(updated )
Script language=“php” HTML tags are interpreted even in secure mode. This may allow a remote attacker to bypass secure mode’s intended restrictions and execute arbitrary PHP code.
References
Detect and mitigate CVE-2014-8350 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →