Description
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to versions 17.1.1, 17.0.3, 16.11.5 or above.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-46832 | An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances. |
References
History
Thu, 29 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-09-17T15:33:21.131Z
Reserved: 2024-06-05T16:02:36.421Z
Link: CVE-2024-5655
Updated: 2024-08-01T21:18:06.633Z
Status : Modified
Published: 2024-06-27T00:15:12.887
Modified: 2024-11-21T09:48:06.140
Link: CVE-2024-5655
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD