CVE-2024-9164

An issue was discovered in GitLab EE affecting all versions starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows running pipelines on arbitrary branches.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

History

13 Dec 2024, 16:33

Type Values Removed Values Added
CPE cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*
cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
References () https://gitlab.com/gitlab-org/gitlab/-/issues/493946 - () https://gitlab.com/gitlab-org/gitlab/-/issues/493946 - Broken Link
References () https://hackerone.com/reports/2711204 - () https://hackerone.com/reports/2711204 - Permissions Required
First Time Gitlab
Gitlab gitlab
CWE NVD-CWE-noinfo

Information

Published : 2024-10-11 13:15

Updated : 2024-12-13 16:33


NVD link : CVE-2024-9164

Mitre link : CVE-2024-9164

CVE.ORG link : CVE-2024-9164


JSON object : View

Products Affected

gitlab

  • gitlab
CWE
CWE-306

Missing Authentication for Critical Function

NVD-CWE-noinfo