CVE-2024-31453: PsiTransfer: Violation of the integrity of file distribution
(updated )
Summary The absence of restrictions on the endpoint, which allows you to create a path for uploading a file in a file distribution, allows an attacker to add arbitrary files to the distribution.
Details Vulnerable endpoint: POST /files
References
Detect and mitigate CVE-2024-31453 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →