An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.
Metrics
Affected Vendors & Products
References
History
Fri, 30 Aug 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-427 |
Fri, 30 Aug 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-451 |
Thu, 29 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitLab
Published: 2024-07-17T01:30:43.332Z
Updated: 2024-09-17T15:32:29.174Z
Reserved: 2024-07-09T05:30:43.165Z
Link: CVE-2024-6595
Updated: 2024-08-01T21:41:03.899Z
Status : Modified
Published: 2024-07-17T02:15:10.130
Modified: 2024-11-21T09:49:57.270
Link: CVE-2024-6595
No data.
ReportizFlow