CVE-2024-8311
MEDIUMGitLab EE <17.2.5-17.3.2 - Auth Bypass
Title source: llmDescription
An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.
Scores
CVSS v3
6.5
EPSS
0.0004
EPSS Percentile
13.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Classification
CWE
CWE-424
Status
published
Affected Products (1)
gitlab/gitlab
< 17.2.5
Timeline
Published
Sep 12, 2024
Tracked Since
Feb 18, 2026