216.73.217.22

CVE-2024-8311

· Published 12/09/2024 19:15 · Modified 18/09/2024 19:12

Labels: CVE-2024-8311 2024-09-12CVE-2024-8311CWE-424NVD-CWE-noinfo[email protected]

Essential information

Published
12/09/2024 19:15
Modified
18/09/2024 19:12
Author
Creator
CVSS
6.5 MEDIUM (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

CVSS metrics

Description

An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
gitlab / gitlab cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*
gitlab / gitlab cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*

References