GitLab: Critical bug lets attackers run pipelines as other users
ID: 79346438-68ff-5386-843f-5a51df70c115
STIX ID: report--79346438-68ff-5386-843f-5a51df70c115
Feed Name: Bleeping Computer
Threat Score
GitLab disclosed and patched a critical vulnerability (CVE-2024-6385, CVSS 9.6) affecting multiple CE/EE versions that can allow attackers to trigger pipelines as arbitrary users; the company released updates and advised immediate upgrades. The report notes related high-impact bugs and past active exploitation of similar GitLab flaws, emphasizing the risk to CI/CD environments and potential supply-chain compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
