cbcvebase.
CVE-2024-8970
published 2024-10-11

CVE-2024-8970: An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4…

PriorityP351high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.59%
43.9th percentile
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

Affected

9 ranges
VendorProductVersion rangeFixed in
debiangitlab< gitlab 17.3.5-3 (sid)gitlab 17.3.5-3 (sid)
gitlabgitlab
gitlabgitlab>= 11.6 < 17.2.917.2.9
gitlabgitlab>= 11.6.0 < 17.2.917.2.9
gitlabgitlab>= 17.3 < 17.3.517.3.5
gitlabgitlab>= 17.3.0 < 17.3.517.3.5
gitlabgitlab>= 17.4 < 17.4.217.4.2
gitlabgitlab>= 17.4.0 < 17.4.217.4.2
gitlabgitlab_ce

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vendor_debian8.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.