CVE-2024-9164

An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

13 Dec 2024, 16:33

Type Values Removed Values Added
References () https://gitlab.com/gitlab-org/gitlab/-/issues/493946 - () https://gitlab.com/gitlab-org/gitlab/-/issues/493946 - Broken Link
References () https://hackerone.com/reports/2711204 - () https://hackerone.com/reports/2711204 - Permissions Required
First Time Gitlab
Gitlab gitlab
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*

15 Oct 2024, 12:58

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en GitLab EE que afecta a todas las versiones desde la 12.5 anterior a la 17.2.9, desde la 17.3, anterior a la 17.3.5 y desde la 17.4 anterior a la 17.4.2, lo que permite ejecutar pipelines en ramas arbitrarias.

11 Oct 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-10-11 13:15

Updated : 2024-12-13 16:33


NVD link : CVE-2024-9164

Mitre link : CVE-2024-9164

CVE.ORG link : CVE-2024-9164


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-306

Missing Authentication for Critical Function

NVD-CWE-noinfo