CVE-2024-9512 — Time-of-check Time-of-use (TOCTOU) Race Condition in Gitlab
Severity
5.9MEDIUMNVD
EPSS
0.0%
top 87.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 12
Description
An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync.
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.2 | Impact: 3.6
Affected Packages5 packages
🔴Vulnerability Details
1GHSA▶
GHSA-g6rr-7jqw-c6hc: An issue has been discovered in GitLab EE affecting all versions prior to 17↗2025-06-12
📋Vendor Advisories
2GitLab▶
CVE-2024-9512: An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been↗2025-06-12
Debian▶
CVE-2024-9512: gitlab - An issue has been discovered in GitLab EE affecting all versions prior to 17.10....↗2024