logo

GitLab Sends Users Scrambling Again With New CI/CD Pipeline Takeover Vuln

ID: e8bc453b-a0f5-52b3-8923-2c25fb3a2e1a

STIX ID: report--e8bc453b-a0f5-52b3-8923-2c25fb3a2e1a

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2024-07-12

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

A critical GitLab CI/CD vulnerability (CVE-2024-6385, CVSS 9.6) allows attackers to execute pipeline jobs as any user, risking code injection, unauthorized access to repositories and data, and disruption of CI/CD processes; multiple GitLab CE/EE versions are affected and GitLab strongly urges immediate upgrades. The report contrasts this flaw with an earlier related issue (CVE-2024-5655), notes that exploitation requires a valid account in the target instance, and emphasizes prompt patching and monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.