GitLab::API::v4 through 0.26 does not verify TLS certificates when connecting to a GitLab server, enabling machine-in-the-middle attacks.
References
Configurations
History
No history.
Information
Published : 2023-04-29 00:15
Updated : 2025-01-31 20:15
NVD link : CVE-2023-31485
Mitre link : CVE-2023-31485
CVE.ORG link : CVE-2023-31485
JSON object : View
Products Affected
gitlab\
- \
CWE
CWE-295
Improper Certificate Validation