CVE-2024-7102
CVSS 3.1 Score 9.6 of 10 (high)
Details
Published Feb 13, 2025
CWE ID 250
Summary
CVE-2024-7102 is a newly disclosed vulnerability affecting GitLab CE/EE versions 16.4 through 17.5.0. This issue permits an attacker to initiate a pipeline under another user's account under specific conditions, posing a potential security risk. The precise circumstances under which this vulnerability can be exploited are yet to be fully understood, but it is recommended that affected organizations upgrade to the latest version, 17.5.0, as soon as possible to mitigate the risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GitLab
Affected Vendors
- GitLab Inc.