CVE-2024-9773

LOW

GitLab 14.9.0-17.8.5, 17.9.0-17.8.2, 17.10.0 - Command Injection via Harbor Registry CLI Integration

Title source: llm
STIX 2.1

Description

An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious code to the CLI commands shown in the UI.

References (2)

Core 2
Core References
Exploit, Issue Tracking issue-tracking permissions-required
https://gitlab.com/gitlab-org/gitlab/-/issues/498557
Permissions Required technical-description exploit permissions-required
https://hackerone.com/reports/2671808

Scores

CVSS v3 3.7
EPSS 0.0004
EPSS Percentile 10.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-77
Status published
Products (2)
gitlab/gitlab 17.10.0
gitlab/gitlab 14.9.0 - 17.8.6
Published Mar 27, 2025
Tracked Since Feb 18, 2026