CyberzSOC

Publication detail
← Back to advisories & guidance

2024-109: Critical vulnerabilities in Gitlab ↗ source

October 11, 2024 CERT-EU Advisory

Summary

It is recommended updating affected assets as soon as possible. The vulnerability CVE-2024-9164, with a CVSS score of 9.6, allows unauthorised users to execute pipelines on branches without appropriate permission, leading to unauthorised code execution. The vulnerability CVE-2024-8970, with a CVSS score of 8.2, allows an attacker to trigger a pipeline as another user under certain conditions, leading to potential unauthorised actions. The vulnerability CVE-2024-8977, with a CVSS score of 8.2, is a Server-Side Request Forgery (SSRF) vulnerability in the Analytics Dashboard, allowing attackers to make unauthorised network requests. It is highly recommended updating affected assets to the latest version as soon as possible.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-9164 9.6 Critical GitLab GitLab An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting fro…
CVE-2024-8970 8.2 High GitLab GitLab An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting f…
CVE-2024-8977 8.2 High GitLab GitLab An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.