HIGH
CVE-2024-5655
CVSS
8.8
Description
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.
Summary dbcve.org
A broken access control vulnerability in GitLab CI/CD pipeline triggering mechanism allows authenticated attackers to trigger pipelines in the name of other users. This is an authorization bypass where the pipeline execution does not properly validate the requesting user's identity against the pipeline's owner.
Mitigation
Upgrade GitLab to version 16.11.5, 17.0.3, or 17.1.1 (or later) to patch the authorization flaw in pipeline triggering.
Weakness (CWE)
CWE-284
Improper Access Control
EPSS Score
7.47%
Probability of exploitation in next 30 days
94.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.