GitLab Patches Important Flaw Permitting Unauthorized Pipeline Job Execution

Sep 12, 2024Ravie LakshmananDevSecOps / Vulnerability

GitLab Patches Important Flaw Permitting Unauthorized Pipeline Job Execution

GitLab on Wednesday launched safety updates to deal with 17 safety vulnerabilities, together with a important flaw that permits an attacker to run pipeline jobs as an arbitrary person.

The problem, tracked as CVE-2024-6678, carries a CVSS rating of 9.9 out of a most of 10.0

“A difficulty was found in GitLab CE/EE affecting all variations ranging from 8.14 previous to 17.1.7, ranging from 17.2 previous to 17.2.5, and ranging from 17.3 previous to 17.3.2, which permits an attacker to set off a pipeline as an arbitrary person underneath sure circumstances,” the corporate stated in an alert.

The vulnerability, together with three high-severity, 11 medium-severity, and two low-severity bugs, have been addressed in variations 17.3.2, 17.2.5, 17.1.7 for GitLab Neighborhood Version (CE) and Enterprise Version (EE).

Cybersecurity

It is value noting that CVE-2024-6678 is the fourth such flaw that GitLab has patched over the previous yr after CVE-2023-5009 (CVSS rating: 9.6), CVE-2024-5655 (CVSS rating: 9.6), and CVE-2024-6385 (CVSS rating: 9.6).

Whereas there isn’t a proof of lively exploitation of the issues, customers are really helpful to use the patches as quickly as attainable to mitigate towards potential threats.

Earlier this Could, U.S. Cybersecurity and Infrastructure Safety Company (CISA) revealed {that a} important GitLab vulnerability (CVE-2023-7028, CVSS rating: 10.0) had come underneath lively exploitation within the wild.

Discovered this text fascinating? Comply with us on Twitter and LinkedIn to learn extra unique content material we publish.


Leave a Reply

Your email address will not be published. Required fields are marked *