Open-Source Security Intelligence

Know every vulnerability
before it knows you.

DevGuard continuously monitors your dependencies and alerts you when CVEs like this one affect your stack — with real-time threat intelligence built for developers.

Search

NCSC-2024-0289

Published Jul 11, 2024·Last modified Jul 11, 2024
Description
Feiten

GitLab heeft een kwetsbaarheid verholpen in GitLab CE/EE

Interpretaties

Een kwaadwillende kan de kwetsbaarheid onder bepaalde omstandigheden misbruiken om een Continuous Integration/Continuous Deployment (CI/CD) pipeline proces te starten als een willekeurige andere gebruiker.

Oplossingen

GitLab heeft updates uitgebracht om de kwetsbaarheid te verhelpen in GitLab CE/EE 17.1.2, 17.0.4, 16.11.6. Zie bijgevoegde referenties voor meer informatie.

Kans

medium

Schade

high

CWE-284

Improper Access Control

Scan your project

Continuously monitor your dependencies and get alerted when vulnerabilities like this one affect your stack.

Checkout DevGuard