GitLab Releases Patch for Critical CI/CD Pipeline Vulnerability and 13 Others
ID: f30c44e4-63ce-593e-b64a-bbdebe3a6121
STIX ID: report--f30c44e4-63ce-593e-b64a-bbdebe3a6121
Feed Name: The Hacker News
GitLab released security updates for Community and Enterprise editions addressing 14 vulnerabilities — most notably CVE-2024-5655 (CVSS 9.6), which could allow triggering CI/CD pipelines as another user. Patches are available in versions 17.1.1, 17.0.3, and 16.11.5; other fixed issues include stored XSS, CSRF against GraphQL, authorization leakage in global search, and OAuth flow abuse. No active exploitation has been reported, and the fixes introduce breaking changes (GraphQL authentication via CI_JOB_TOKEN disabled by default and altered pipeline behavior when a merge request is re-targeted).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
