PT-2024-5344 · Gitlab · Gitlab Ce/Ee+1
Ameya Darshan
·
Published
2024-07-10
·
Updated
2024-08-30
·
CVE-2024-6595
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
GitLab CE/EE versions 11.8 through 16.11.6
GitLab CE/EE versions 17.0 through 17.0.4
GitLab CE/EE versions 17.1 through 17.1.2
Description
An issue was discovered where it was possible to upload an NPM package with conflicting package data. This issue is related to an uncontrolled search path element. Exploitation of this issue may allow a remote attacker to upload a package with conflicting data.
Recommendations
For versions 11.8 through 16.11.6, update to a version after 16.11.6 to resolve the issue.
For versions 17.0 through 17.0.4, update to a version after 17.0.4 to resolve the issue.
For versions 17.1 through 17.1.2, update to a version after 17.1.2 to resolve the issue.
As a temporary workaround, consider restricting the upload of NPM packages until a patch is available.
Exploit
Fix
Untrusted Search Path
UI Misrepresentation of Critical Information
Unrestricted File Upload
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Gitlab
Gitlab Ce/Ee