CVE-2024-8402
CVE-2024-8402
Título es
CVE-2024-8402
Jue, 13/03/2025 – 06:15
Tipo
CWE-77
Gravedad 2.0 Txt
Pendiente de análisis
Título en
CVE-2024-8402
Descripción en
An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a Maintainer to introduce malicious code.
13/03/2025
13/03/2025
Vector CVSS:3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N
Gravedad 3.1 (CVSS 3.1 Base Score)
3.70
Gravedad 3.1 Txt Gravedad 3.1 (CVSS 3.1 Base Score)
LOW
Referencias
https://gitlab.com/gitlab-org/gitlab/-/issues/482813
https://hackerone.com/reports/2601569
Enviar en el boletín
Off
