An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prior to 17.2.4, and starting from 17.3 prior to 17.3.1, which allows an attacker to create a branch with the same name as a deleted tag.
2024-08-22T16:15:10.377
2024-09-11T16:49:28.650
Analyzed
CVSSv3.1: 5.7 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 17.1.6 | Yes |
Application | gitlab | gitlab | < 17.2.4 | Yes |
Application | gitlab | gitlab | < 17.3.1 | Yes |
Application | gitlab | gitlab | < 17.1.6 | Yes |
Application | gitlab | gitlab | < 17.2.4 | Yes |
Application | gitlab | gitlab | < 17.3.1 | Yes |