An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/479315 | Broken Link |
Configurations
Configuration 1 (hide)
|
History
18 Sep 2024, 19:12
Type | Values Removed | Values Added |
---|---|---|
First Time |
Gitlab gitlab
Gitlab |
|
CPE | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | |
References | () https://gitlab.com/gitlab-org/gitlab/-/issues/479315 - Broken Link | |
CWE | NVD-CWE-noinfo | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 6.5 |
12 Sep 2024, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-12 19:15
Updated : 2024-09-18 19:12
NVD link : CVE-2024-8311
Mitre link : CVE-2024-8311
JSON object : View
Products Affected
gitlab
- gitlab
CWE