logo

GitLab warns of critical pipeline execution vulnerability

ID: 86f995e3-152f-522c-b94e-0125c0e30dbb

STIX ID: report--86f995e3-152f-522c-b94e-0125c0e30dbb

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-09-12

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

GitLab released security updates (17.3.2, 17.2.5, 17.1.7) addressing 18 issues including a critical CVE-2024-6678 (CVSS 9.9) that can allow attackers to trigger pipelines or execute environment stop actions as arbitrary users; several other high-severity flaws (CVE-2024-8640, CVE-2024-8635, CVE-2024-8124, CVE-2024-8641) are also patched. The bulletin lists affected version ranges and provides links for updates and runner package information, and strongly recommends immediate upgrades for impacted installations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.