CVE-2024-6502: GitLab
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prior to 17.2.4, and starting from 17.3 prior to 17.3.1, which allows an attacker to create a branch with the same name as a deleted tag.
Affected products
- GitLab GitLab: from 8.2.0, before 17.1.6 (fixed in 17.1.6); from 17.2.0, before 17.2.4 (fixed in 17.2.4); from 17.3.0, before 17.3.1 (fixed in 17.3.1)
Published 2024-08-22. Last modified 2026-06-17.