An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-09-12 19:15
Updated : 2024-11-21 09:53
NVD link : CVE-2024-8311
Mitre link : CVE-2024-8311
CVE.ORG link : CVE-2024-8311
JSON object : View
Products Affected
gitlab
- gitlab
CWE