HIGH

CVE-2024-9693

Gitlab GitLab 2024-11-14 CVSS v3.1
CVSS
8.8

Description

An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed unauthorized access to the Kubernetes agent in a cluster under specific configurations.

Summary dbcve.org

This is an authorization bypass vulnerability in GitLab's Kubernetes agent feature that allows unauthorized access to the Kubernetes agent in a cluster under specific configurations. The issue affects multiple version ranges across GitLab 16.x, 17.x and requires updating to the patched versions (17.3.7, 17.4.4, or 17.5.2).

Mitigation

Upgrade GitLab to version 17.3.7, 17.4.4, or 17.5.2 or later. Review and audit Kubernetes agent configurations and cluster access permissions after patching.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.55%
Probability of exploitation in next 30 days
44.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE