logo

GitLab Patches Critical Flaw Allowing Unauthorized Pipeline Jobs

ID: 2631e40d-a231-51d6-9ce1-c0a1a930d306

STIX ID: report--2631e40d-a231-51d6-9ce1-c0a1a930d306

Feed Name: The Hacker News

Threat Score
72/100

Date Published: 2024-07-11

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

GitLab released fixes for several security flaws, including a critical pipeline privilege vulnerability (CVE-2024-6385, CVSS 9.6) that can allow attackers to run pipeline jobs as arbitrary users; earlier similar bugs (CVE-2024-5655) and a medium-severity namespace URL modification issue (CVE-2024-5257) were also patched. The article also notes critical and medium-severity patches from Citrix and Broadcom for other products, and highlights a CISA/FBI bulletin urging vendors to eliminate OS command injection flaws and adopt stronger access controls and zero-trust-like architectures.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.