Possible upload of conflicting NPM package data

CVE-2024-6595
5.3MEDIUM

Key Information

Vendor
Gitlab
Status
Gitlab
Vendor
CVE Published:
17 July 2024

Summary

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.

Affected Version(s)

GitLab < 16.11.6

GitLab < 17.0.4

GitLab < 17.1.2

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Risk change from: 5.3 to: 3 - (LOW)

  • Vulnerability published.

Collectors

NVD DatabaseMitre Database

Credit

Thanks vulnerability was found internally by a GitLab team member [Ameya Darshan](https://gitlab.com/ameyadarshan). Thanks to [Darcy Clarke](https://x.com/darcy) for their work on [manifest confusion](https://blog.vlt.sh/blog/the-massive-hole-in-the-npm-ecosystem).
.