GHSA-c9v7-wmwj-vf6x: Withdrawn Advisory: SFTP is possible on the Proxy server for any user with SFTP access
(updated )
An attacker that has access to nodes within the cluster may be able to SFTP to the Proxy Service. The user’s permissions on the Proxy server are still respected, so files can only be read or modified on the Proxy if the user has system access to read or write to them.
References
Detect and mitigate GHSA-c9v7-wmwj-vf6x with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →