logo

GitLab warns of critical arbitrary branch pipeline execution flaw

ID: b4cc9d42-a3ee-578f-b0e1-2dcd73096617

STIX ID: report--b4cc9d42-a3ee-578f-b0e1-2dcd73096617

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-10-10

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

GitLab published security updates addressing multiple flaws in Community and Enterprise Editions, including CVE-2024-9164 — a critical (CVSS 9.6) arbitrary branch pipeline execution vulnerability that permits unauthorized users to trigger CI/CD pipelines on any repository branch and could lead to code execution or sensitive data exposure; affected versions and fixed releases (17.4.2, 17.3.5, 17.2.9) are provided along with several other high- and medium-severity CVEs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.