MEDIUM

CVE-2024-8311

Gitlab GitLab 2024-09-12 CVSS v3.1
CVSS
6.5

Description

An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.

Summary dbcve.org

This GitLab EE vulnerability allows authenticated users to bypass variable overwrite protection by including CI/CD templates. Attackers can circumvent security controls meant to protect sensitive pipeline variables from modification.

Mitigation

Upgrade GitLab EE to version 17.2.5, 17.3.2, or later to patch the vulnerability.

Weakness (CWE)

CWE-424

EPSS Score

0.61%
Probability of exploitation in next 30 days
47.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE