CVE-2024-27093: Minder trusts client-provided mapping from repo name to upstream ID
(updated )
When using a modified client or the grpc interface directly, the RegisterRepository
call accepts both the repository owner / repo and the repo_id. Furthermore, these two are not checked for matching before registering webhooks and data in the database.
References
Detect and mitigate CVE-2024-27093 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →