logo

Patch Now: GitLab Fixes Major Vulnerabilities in All Versions

ID: 1c1a16d5-e352-52a6-981f-7fab0078d06f

STIX ID: report--1c1a16d5-e352-52a6-981f-7fab0078d06f

Feed Name: The Cyber Express

Threat Score
75/100

Date Published: 2024-10-15

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

GitLab released critical patches for CE/EE (17.4.2, 17.3.5, 17.2.9) addressing multiple CVEs — notably a critical pipeline-execution flaw (CVE-2024-9164, CVSS 9.6) and several high- and medium-severity issues (user impersonation CVE-2024-8970, SSRF CVE-2024-8977, XSS CVE-2024-6530, deploy-key push CVE-2024-9623) affecting a wide range of versions; self-managed instances are urged to upgrade immediately while GitLab.com is already patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.