An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.
Metrics
Affected Vendors & Products
References
History
Fri, 30 Aug 2024 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-427 |
Fri, 30 Aug 2024 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-451 |
Thu, 29 Aug 2024 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
MITRE
Status: PUBLISHED
Assigner: GitLab
Published: 2024-07-17T01:30:43.332Z
Updated: 2024-09-17T15:32:29.174Z
Reserved: 2024-07-09T05:30:43.165Z
Link: CVE-2024-6595
Vulnrichment
Updated: 2024-08-01T21:41:03.899Z
NVD
Status : Modified
Published: 2024-07-17T02:15:10.130
Modified: 2024-11-21T09:49:57.270
Link: CVE-2024-6595
Redhat
No data.