GitLab warns of critical arbitrary branch pipeline execution flaw
ID: b4cc9d42-a3ee-578f-b0e1-2dcd73096617
STIX ID: report--b4cc9d42-a3ee-578f-b0e1-2dcd73096617
Feed Name: Bleeping Computer
Threat Score
GitLab published security updates addressing multiple flaws in Community and Enterprise Editions, including CVE-2024-9164 — a critical (CVSS 9.6) arbitrary branch pipeline execution vulnerability that permits unauthorized users to trigger CI/CD pipelines on any repository branch and could lead to code execution or sensitive data exposure; affected versions and fixed releases (17.4.2, 17.3.5, 17.2.9) are provided along with several other high- and medium-severity CVEs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
