CVE-2025-54583 is a medium-severity vulnerability affecting GitProxy versions 1.19.1 and below, allowing authenticated attackers to bypass security policies and push unauthorized code to Git repositories. This flaw, categorized as CWE-863, has a CVSS score of 6.5, indicating a network-exploitable vulnerability with low attack complexity and high integrity impact, as it enables the introduction of secrets or unwanted changes. While the EPSS score is low and it's not listed in CISA's KEV catalog, suggesting no active exploitation, there are currently no known public exploits or significant community discussion surrounding this vulnerability. Organizations using affected GitProxy versions should upgrade to 1.19.2 to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.19.2CPE matchmatch criteria | cpe:2.3:a:finos:gitproxy:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.