logo

Critical GitLab Bug Threatens Software Development Pipelines

ID: dd8334ee-a0c1-54ba-8e67-17d2b549b303

STIX ID: report--dd8334ee-a0c1-54ba-8e67-17d2b549b303

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2024-06-28

Date Updated: 2026-04-21

Author: Nate Nelson, Contributing Writer

...
...

GitLab released patches addressing 14 security issues including a critical vulnerability (CVE-2024-5655, CVSS 9.6) affecting multiple versions that can let an attacker run pipelines as another user—potentially exposing private repositories and enabling code manipulation or exfiltration; GitLab reports no evidence of in-the-wild exploitation, but the flaw carries operational and regulatory compliance risks for organizations using affected GitLab versions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.