Critical GitLab bug lets attackers run pipelines as any user
ID: 4aaca24b-6668-55c0-b063-2366ba5e4e19
STIX ID: report--4aaca24b-6668-55c0-b063-2366ba5e4e19
Feed Name: Bleeping Computer
Threat Score
A critical GitLab vulnerability (CVE-2024-5655, CVSS 9.6) affecting multiple CE/EE versions could allow attackers to trigger pipelines as any user; GitLab has released patches (16.11.5, 17.0.3, 17.1.1) and urges immediate upgrades. The update also addresses three additional high-severity issues (CVE-2024-4901, CVE-2024-4994, CVE-2024-6323) and introduces breaking changes to pipeline behavior and GraphQL authentication.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
