HIGH

CVE-2024-5655

Gitlab GitLab 2024-06-27 CVSS v3.1
CVSS
8.8

Description

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.

Summary dbcve.org

A broken access control vulnerability in GitLab CI/CD pipeline triggering mechanism allows authenticated attackers to trigger pipelines in the name of other users. This is an authorization bypass where the pipeline execution does not properly validate the requesting user's identity against the pipeline's owner.

Mitigation

Upgrade GitLab to version 16.11.5, 17.0.3, or 17.1.1 (or later) to patch the authorization flaw in pipeline triggering.

Weakness (CWE)

CWE-284 Improper Access Control

EPSS Score

7.47%
Probability of exploitation in next 30 days
94.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE