Description
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.
No analysis available yet.
Remediation
Vendor Solution
Upgrade to versions 17.1.2, 17.0.4, 16.11.6 or above.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47492 | An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances. |
References
History
Wed, 18 Sep 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 29 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* |
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-09-18T13:11:50.553Z
Reserved: 2024-06-27T09:30:39.434Z
Link: CVE-2024-6385
Updated: 2024-08-01T21:41:03.228Z
Status : Modified
Published: 2024-07-11T07:15:06.123
Modified: 2024-11-21T09:49:32.767
Link: CVE-2024-6385
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD