logo

GitLab: Critical bug lets attackers run pipelines as other users

ID: 79346438-68ff-5386-843f-5a51df70c115

STIX ID: report--79346438-68ff-5386-843f-5a51df70c115

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2024-07-10

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

GitLab disclosed and patched a critical vulnerability (CVE-2024-6385, CVSS 9.6) affecting multiple CE/EE versions that can allow attackers to trigger pipelines as arbitrary users; the company released updates and advised immediate upgrades. The report notes related high-impact bugs and past active exploitation of similar GitLab flaws, emphasizing the risk to CI/CD environments and potential supply-chain compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.