Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5qwh-g35c-5mmm

Опубликовано: 17 июл. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 3

Описание

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.

EPSS

Процентиль: 20%
0.00063
Низкий

3 Low

CVSS3

Дефекты

CWE-427
CWE-434
CWE-451

Связанные уязвимости

CVSS3: 3
ubuntu
около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.

CVSS3: 3
nvd
около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2 where it was possible to upload an NPM package with conflicting package data.

CVSS3: 3
debian
около 1 года назад

An issue was discovered in GitLab CE/EE affecting all versions startin ...

CVSS3: 3
fstec
около 1 года назад

Уязвимость программной платформы на базе git для совместной работы над кодом GitLab, связанная с неконтролируемым элементом пути поиска, позволяющая нарушителю загрузить пакет NPM с конфликтующими данными пакета

EPSS

Процентиль: 20%
0.00063
Низкий

3 Low

CVSS3

Дефекты

CWE-427
CWE-434
CWE-451