Supply Chain Security

GitLab Ships Update for Critical Pipeline Execution Vulnerability

GitLab issues an advisory for a critical-severity vulnerability that allows an attacker to trigger a pipeline as another user.

GitLab issues an advisory for a critical-severity vulnerability that allows an attacker to trigger a pipeline as another user.

DevOps platform GitLab has pushed out security updates that address six vulnerabilities in GitLab Community Edition (CE) and Enterprise Edition (EE), including a critical-severity bug with serious implications.

The issue, tracked as CVE-2024-6385 (CVSS score 9.6/10), allows an attacker to trigger a pipeline as another users, under certain circumstances, and impacts GitLab CE/EE versions 15.8 to 16.11.5, 17.0.0 to 17.0.3, and 17.1.0 to 17.1.1.

Reported via GitLab’s bug bounty program on HackerOne, the security defect was addressed with the release of GitLab CE/EE versions 17.1.2, 17.0.4, and 16.11.6.

The GitLab advisory does not include further details on the security defect or how it was resolved.

In an emailed comment to SecurityWeek, Contrast Security CISO David Lindner warned that successful exploitation of the bug “could enable attackers to run malicious code, access sensitive data and compromise software integrity”. 

Patches for CVE-2024-6385 were released roughly two weeks after the DevOps platform addressed another flaw (CVE-2024-5655) that allows attackers to run pipeline jobs as another user.

Advertisement. Scroll to continue reading.

The latest GitLab security updates also resolve a medium-severity bug that could allow a user with a custom role to modify the URL for a group namespace.

The remaining four issues resolved with the latest GitLab CE/EE versions are low-severity flaws leading to the inappropriate creation of project-level deploy tokens, the upload of NPM packages with conflicting package data, users with a custom role banning group members, and subdomain takeover in GitLab Pages.

GitLab makes no mention of any of these vulnerabilities being exploited in the wild. Users are advised to update their instances as soon as possible, as threat actors are known to have exploited GitLab vulnerabilities for which patches had been released.

Related: GitLab Patches Critical Pipeline Execution Vulnerability

Related: Thousands of GitLab Instances Unpatched Against Password Reset Bug

Related: GitLab Patches Critical Pipeline Execution Vulnerability

Related: GitLab Security Update Patches Critical Vulnerability

Related Content

Vulnerabilities

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.

Vulnerabilities

CVE-2026-19478 can be exploited without authentication to modify or delete public projects and user data.

Vulnerabilities

The security defect allows unauthenticated attackers to modify or delete user data and public projects.

Vulnerabilities

The latest GitLab CE/EE updates address 13 vulnerabilities, including three high-severity defects.

Vulnerabilities

Fixes were rolled out for over two dozen vulnerabilities, including critical- and high-severity bugs.

Data Breaches

Hackers claim to have stolen 28,000 private repositories, including data associated with major companies that use Red Hat services.

Vulnerabilities

GitLab and Atlassian have released patches for over a dozen vulnerabilities in their products, including high-severity bugs.

Vulnerabilities

The latest GitLab update resolves eight vulnerabilities, including critical- and high-severity pipeline execution flaws.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version