HIGH
CVE-2024-9163
CVSS
7.5
Description
A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs.
Summary dbcve.org
A business logic error in GitLab allows an attacker to cause branch name confusion in confidential merge requests (MRs). The flaw enables manipulation of branch identification in the MR workflow, potentially allowing unauthorized code changes or information disclosure in private/comfidential MRs.
Mitigation
Upgrade GitLab to version 17.10.7, 17.11.3, 18.0.1 or later. If immediate upgrade is not feasible, implement additional access controls and monitoring on merge request operations.
Weakness (CWE)
CWE-451
EPSS Score
0.39%
Probability of exploitation in next 30 days
33.2th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.