GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1 and below allow users to push to remote repositories while bypassing policies and explicit approvals. Since checks and plugins are skipped, code containing secrets or unwanted changes could be pushed into a repository. This is fixed in version 1.19.2.
History

Fri, 01 Aug 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Finos gitproxy
CPEs cpe:2.3:a:finos:gitproxy:*:*:*:*:*:*:*:*
Vendors & Products Finos gitproxy
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}


Thu, 31 Jul 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Finos
Finos git-proxy
Vendors & Products Finos
Finos git-proxy

Wed, 30 Jul 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 30 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
Description GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1 and below allow users to push to remote repositories while bypassing policies and explicit approvals. Since checks and plugins are skipped, code containing secrets or unwanted changes could be pushed into a repository. This is fixed in version 1.19.2.
Title GitProxy bypasses approvals when pushing multiple branches
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-07-30T19:59:44.317Z

Updated: 2025-07-30T20:13:10.804Z

Reserved: 2025-07-25T16:19:16.093Z

Link: CVE-2025-54583

cve-icon Vulnrichment

Updated: 2025-07-30T20:11:58.804Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-30T20:15:38.177

Modified: 2025-08-01T20:04:33.990

Link: CVE-2025-54583

cve-icon Redhat

No data.