CVE-2014-0177: Arbitrary File Overwrite in hub
The am function in lib/hub/commands.rb
in hub allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file.
References
Detect and mitigate CVE-2014-0177 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →