An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/417975 | Issue Tracking |
https://blog.vlt.sh/blog/the-massive-hole-in-the-npm-ecosystem | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
19 Jul 2024, 14:52
Type | Values Removed | Values Added |
---|---|---|
First Time |
Gitlab gitlab
Gitlab |
|
References | () https://gitlab.com/gitlab-org/gitlab/-/issues/417975 - Issue Tracking | |
References | () https://blog.vlt.sh/blog/the-massive-hole-in-the-npm-ecosystem - Exploit, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
CPE | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
|
CWE | CWE-434 |
17 Jul 2024, 02:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-07-17 02:15
Updated : 2024-08-30 14:15
NVD link : CVE-2024-6595
Mitre link : CVE-2024-6595
JSON object : View
Products Affected
gitlab
- gitlab
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type