An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 09:53
Type | Values Removed | Values Added |
---|---|---|
References |
|
18 Sep 2024, 19:12
Type | Values Removed | Values Added |
---|---|---|
First Time |
Gitlab
Gitlab gitlab |
|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | |
References | () https://gitlab.com/gitlab-org/gitlab/-/issues/479315 - Broken Link | |
Summary |
|
12 Sep 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-12 19:15
Updated : 2024-11-21 09:53
NVD link : CVE-2024-8311
Mitre link : CVE-2024-8311
CVE.ORG link : CVE-2024-8311
JSON object : View
Products Affected
gitlab
- gitlab
CWE