Attackers don’t need credentials or user interaction to exploit the flaw which could enable supply chain attacks in self-hosted code repositories.