HIGH

CVE-2024-9163

Gitlab GitLab 2025-05-23 CVSS v3.1
CVSS
7.5

Description

A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs.

Summary dbcve.org

A business logic error in GitLab allows an attacker to cause branch name confusion in confidential merge requests (MRs). The flaw enables manipulation of branch identification in the MR workflow, potentially allowing unauthorized code changes or information disclosure in private/comfidential MRs.

Mitigation

Upgrade GitLab to version 17.10.7, 17.11.3, 18.0.1 or later. If immediate upgrade is not feasible, implement additional access controls and monitoring on merge request operations.

Weakness (CWE)

CWE-451

EPSS Score

0.39%
Probability of exploitation in next 30 days
33.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE