An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47660 | An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data. |
Fixes
Solution
Upgrade to versions 16.11.6, 17.0.4, 17.1.2 or above.
Workaround
No workaround given by the vendor.
References
History
Fri, 30 Aug 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-427 |
Fri, 30 Aug 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-451 |
Thu, 29 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-09-17T15:32:29.174Z
Reserved: 2024-07-09T05:30:43.165Z
Link: CVE-2024-6595
Updated: 2024-08-01T21:41:03.899Z
Status : Modified
Published: 2024-07-17T02:15:10.130
Modified: 2024-11-21T09:49:57.270
Link: CVE-2024-6595
No data.
OpenCVE Enrichment
No data.
EUVD