• Menu
  • Skip to main content
  • Skip to primary sidebar

All Tech News

Latest Technology News

Urgent: GitLab Patches Critical Flaw Allowing Unauthorized Pipeline Job Execution

You are here: Home / Cyber Security News / Urgent: GitLab Patches Critical Flaw Allowing Unauthorized Pipeline Job Execution

GitLab on Wednesday released security updates to address 17 security vulnerabilities, including a critical flaw that allows an attacker to run pipeline jobs as an arbitrary user.

The issue, tracked as CVE-2024-6678, carries a CVSS score of 9.9 out of a maximum of 10.0

“An issue was discovered in GitLab CE/EE affecting all versions starting from 8.14 prior to 17.1.7, starting from 17.2 prior to 17.2.5, and starting from 17.3 prior to 17.3.2, which allows an attacker to trigger a pipeline as an arbitrary user under certain circumstances,” the company said in an alert.

The vulnerability, along with three high-severity, 11 medium-severity, and two low-severity bugs, have been addressed in versions 17.3.2, 17.2.5, 17.1.7 for GitLab Community Edition (CE) and Enterprise Edition (EE).

It’s worth noting that CVE-2024-6678 is the fourth such flaw that GitLab has patched over the past year after CVE-2023-5009 (CVSS score: 9.6), CVE-2024-5655 (CVSS score: 9.6), and CVE-2024-6385 (CVSS score: 9.6).

While there is no evidence of active exploitation of the flaws, users are recommended to apply the patches as soon as possible to mitigate against potential threats.

Earlier this May, U.S. Cybersecurity and Infrastructure Security Agency (CISA) revealed that a critical GitLab vulnerability (CVE-2023-7028, CVSS score: 10.0) had come under active exploitation in the wild.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

Some parts of this article are sourced from:
thehackernews.com

Previous Post: « Beware: New Vo1d Malware Infects 1.3 Million Android TV Boxes Worldwide
Next Post: New Android Malware ‘Ajina.Banker’ Steals Financial Data and Bypasses 2FA via Telegram »

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Recent Posts

  • New Malware Campaign Uses Cloudflare Tunnels to Deliver RATs via Phishing Chains
  • 1,500+ Minecraft Players Infected by Java Malware Masquerading as Game Mods on GitHub
  • FedRAMP at Startup Speed: Lessons Learned
  • Water Curse Hijacks 76 GitHub Accounts to Deliver Multi-Stage Malware Campaign
  • Ex-CIA Analyst Sentenced to 37 Months for Leaking Top Secret National Defense Documents

Copyright © 2025 · AllTech.News, All Rights Reserved.