Patch Now: GitLab Fixes Major Vulnerabilities in All Versions
ID: 1c1a16d5-e352-52a6-981f-7fab0078d06f
STIX ID: report--1c1a16d5-e352-52a6-981f-7fab0078d06f
Feed Name: The Cyber Express
Threat Score
GitLab released critical patches for CE/EE (17.4.2, 17.3.5, 17.2.9) addressing multiple CVEs — notably a critical pipeline-execution flaw (CVE-2024-9164, CVSS 9.6) and several high- and medium-severity issues (user impersonation CVE-2024-8970, SSRF CVE-2024-8977, XSS CVE-2024-6530, deploy-key push CVE-2024-9623) affecting a wide range of versions; self-managed instances are urged to upgrade immediately while GitLab.com is already patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
