CVE-2024-3958Code Injection in Gitlab

CWE-94Code Injection5 documents5 sources
Severity
6.5MEDIUMNVD
EPSS
0.1%
top 72.50%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 8

Description

An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found that allows someone to abuse a discrepancy between the Web application display and the git command line interface to social engineer victims into cloning non-trusted code.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5gitlab/gitlab17.117.1.4+1
NVDgitlab/gitlab17.1.017.1.4+2
debiandebian/gitlab< gitlab 17.3.5-2 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2024-3958: An issue has been discovered in GitLab CE/EE affecting all versions before 172024-08-08
GHSA
GHSA-f8rc-7cqg-v9mm: An issue has been discovered in GitLab CE/EE affecting all versions before 172024-08-08

📋Vendor Advisories

2
GitLab
CVE-2024-3958: An issue has been discovered in GitLab CE/EE affecting all versions before 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2. An issue was found2024-08-08
Debian
CVE-2024-3958: gitlab - An issue has been discovered in GitLab CE/EE affecting all versions before 17.0....2024