gitlab-rails-ee-17.3
Chainguard
17.3.1-r1
9.8
CVSS V3
Status
Fixed version
17.3.1-r1Status
Impact
This vulnerability comes from a gem devfile which is linked with go-code here https://gitlab.com/gitlab-org/gitlab/-/blame/master/Gemfile#L715 the repo https://gitlab.com/gitlab-org/ruby/gems/devfile-gem is used for remote workspaces in gitlab and requires an upstream fix.
Status