CVE-2024-8266
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Published Feb 13, 2025
CWE ID 250
Summary
CVE-2024-8266 is a vulnerability affecting GitLab CE/EE versions 17.1 to 17.5.9 and 17.6.0 prior to the scheduled release. An attacker with maintainer role can exploit this issue to trigger pipelines as the project owner under specific conditions. This bypasses the intended access control, potentially leading to unauthorized pipeline executions and subsequent unintended consequences. It is recommended that affected organizations upgrade to the latest versions to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- GitLab
Affected Vendors
- GitLab Inc.