PT-2024-37674 · Gitlab · Gitlab Ce/Ee+1

Byst4Nly0N

·

Published

2024-08-22

·

Updated

2024-09-11

·

CVE-2024-6502

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 8.2 through 17.1.6 GitLab CE/EE versions 17.2 through 17.2.4 GitLab CE/EE versions 17.3 through 17.3.1
Description An issue was discovered in GitLab CE/EE, which allows an attacker to create a branch with the same name as a deleted tag.
Recommendations For versions 8.2 through 17.1.6, update to version 17.1.6 or later. For versions 17.2 through 17.2.4, update to version 17.2.4 or later. For versions 17.3 through 17.3.1, update to version 17.3.1 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

BIT-GITLAB-2024-6502
CVE-2024-6502

Affected Products

Gitlab
Gitlab Ce/Ee