GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1 and below allow users to push to remote repositories while bypassing policies and explicit approvals. Since checks and plugins are skipped, code containing secrets or unwanted changes could be pushed into a repository. This is fixed in version 1.19.2.
Metrics
Affected Vendors & Products
References
History
Fri, 01 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Finos gitproxy
|
|
CPEs | cpe:2.3:a:finos:gitproxy:*:*:*:*:*:*:*:* | |
Vendors & Products |
Finos gitproxy
|
|
Metrics |
cvssV3_1
|
Thu, 31 Jul 2025 10:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Finos
Finos git-proxy |
|
Vendors & Products |
Finos
Finos git-proxy |
Wed, 30 Jul 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 30 Jul 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1 and below allow users to push to remote repositories while bypassing policies and explicit approvals. Since checks and plugins are skipped, code containing secrets or unwanted changes could be pushed into a repository. This is fixed in version 1.19.2. | |
Title | GitProxy bypasses approvals when pushing multiple branches | |
Weaknesses | CWE-863 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-07-30T19:59:44.317Z
Updated: 2025-07-30T20:13:10.804Z
Reserved: 2025-07-25T16:19:16.093Z
Link: CVE-2025-54583

Updated: 2025-07-30T20:11:58.804Z

Status : Analyzed
Published: 2025-07-30T20:15:38.177
Modified: 2025-08-01T20:04:33.990
Link: CVE-2025-54583

No data.