CVE-2024-6502Incorrect Provision of Specified Functionality in Gitlab

Severity
6.5MEDIUMNVD
EPSS
0.1%
top 78.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 22

Description

An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prior to 17.2.4, and starting from 17.3 prior to 17.3.1, which allows an attacker to create a branch with the same name as a deleted tag.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5gitlab/gitlab8.217.1.6+2
NVDgitlab/gitlab8.2.017.1.6+2
debiandebian/gitlab< gitlab 17.3.5-2 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2024-6502: An issue was discovered in GitLab CE/EE affecting all versions starting from 82024-08-22
GHSA
GHSA-j5xm-2wp4-36g2: An issue was discovered in GitLab CE/EE affecting all versions starting from 82024-08-22

📋Vendor Advisories

2
GitLab
CVE-2024-6502: An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prior to 17.2.4, and starting from2024-08-22
Debian
CVE-2024-6502: gitlab - An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2...2024