HIGH
GitProxy bypasses approvals when pushing multiple branches
Published Jul 30, 2025
8.3
HIGHCVSS 4.0
EPSS 0.46%
Description
GitProxy is an application that stands between developers and a Git remote endpoint (e.g., github.com). Versions 1.19.1 and below allow users to push to remote repositories while bypassing policies and explicit approvals. Since checks and plugins are skipped, code containing secrets or unwanted changes could be pushed into a repository. This is fixed in version 1.19.2.
Affected products
-
- Version < 1.19.2StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
@finos/git-proxy
npm
Introduced 0 Fixed 1.19.2
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | @finos/git-proxy | 0 | 1.19.2 |
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://github.com/advisories/GHSA-qr93-8wwf-22g4 Advisory
- https://github.com/finos/git-proxy/commit/a620a2f33c39c78e01783a274580bf822af3cc3a x_refsource_MISCPatch
- https://github.com/finos/git-proxy/commit/bd2ecb2099cba21bca3941ee4d655d2eb887b3a9 x_refsource_MISCPatch
- https://github.com/finos/git-proxy/releases/tag/v1.19.2 x_refsource_MISCPatchRelease Notes
- https://github.com/finos/git-proxy/security/advisories/GHSA-qr93-8wwf-22g4 x_refsource_CONFIRMExploitThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-54583
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-qr93-8wwf-22g4 | Advisory | |
| https://github.com/finos/git-proxy/commit/a620a2f33c39c78e01783a274580bf822af3cc3a | x_refsource_MISCPatch | |
| https://github.com/finos/git-proxy/commit/bd2ecb2099cba21bca3941ee4d655d2eb887b3a9 | x_refsource_MISCPatch | |
| https://github.com/finos/git-proxy/releases/tag/v1.19.2 | x_refsource_MISCPatchRelease Notes | |
| https://github.com/finos/git-proxy/security/advisories/GHSA-qr93-8wwf-22g4 | x_refsource_CONFIRMExploitThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-54583 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jul 30, 2025
Updated Jul 30, 2025
Reserved Jul 25, 2025
Link CVE-2025-54583
CISA Vulnrichment
GHSA-QR93-8WWF-22G4 Updated Jul 30, 2025