MEDIUM
CVE-2024-8311
CVSS
6.5
Description
An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.
Summary dbcve.org
This GitLab EE vulnerability allows authenticated users to bypass variable overwrite protection by including CI/CD templates. Attackers can circumvent security controls meant to protect sensitive pipeline variables from modification.
Mitigation
Upgrade GitLab EE to version 17.2.5, 17.3.2, or later to patch the vulnerability.
Weakness (CWE)
CWE-424
EPSS Score
0.61%
Probability of exploitation in next 30 days
47.8th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.