GitLab Patches Critical Flaw Allowing Unauthorized Pipeline Jobs
ID: 2631e40d-a231-51d6-9ce1-c0a1a930d306
STIX ID: report--2631e40d-a231-51d6-9ce1-c0a1a930d306
Feed Name: The Hacker News
GitLab released fixes for several security flaws, including a critical pipeline privilege vulnerability (CVE-2024-6385, CVSS 9.6) that can allow attackers to run pipeline jobs as arbitrary users; earlier similar bugs (CVE-2024-5655) and a medium-severity namespace URL modification issue (CVE-2024-5257) were also patched. The article also notes critical and medium-severity patches from Citrix and Broadcom for other products, and highlights a CISA/FBI bulletin urging vendors to eliminate OS command injection flaws and adopt stronger access controls and zero-trust-like architectures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
