Input Validation Flaw in GitLab EE Affects Version Range
CVE-2024-9773
Key Information:
Badges
Summary
A vulnerability found in GitLab EE affects a range of versions due to an input validation flaw in the Harbor registry integration. This issue allows maintainers to potentially introduce malicious code into the Command-Line Interface (CLI) commands presented in the user interface, leading to a risk of exploitation. It is crucial for users to implement necessary updates and review configuration settings to protect their environments.
Affected Version(s)
GitLab 14.9 < 17.8.6
GitLab 17.9 < 17.9.3
GitLab 17.10 < 17.10.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved