Description
BBOT's gitlab module could be abused to disclose a GitLab API key to an attacker controlled server with a malicious formatted git URL.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
0.0.0
References
blog.blacklanternsecurity.com/...security-advisory-gitdumper