Race Condition Vulnerability in GitLab Affects Multiple Versions and Users
CVE-2024-11222

6.4MEDIUM

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
16 September 2026

What is CVE-2024-11222?

A race condition in GitLab CE/EE creates a security flaw that may allow a developer user to execute actions under the context of another user's merge request commit. This vulnerability arises during the pipeline creation process, potentially compromising user permissions and project integrity. GitLab has addressed this issue in specific versions, urging users to update to the latest versions to mitigate this risk.

Affected Version(s)

GitLab 13.0 < 19.1.8

GitLab 19.2 < 19.2.6

GitLab 19.3 < 19.3.2

References

CVSS V3.1

Score:
6.4
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [xorz](https://hackerone.com/xorz) for reporting this vulnerability through our HackerOne bug bounty program
.