CVE-2024-9773

LOW

Gitlab < 17.8.6 - Command Injection

Title source: rule

Description

An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious code to the CLI commands shown in the UI.

Scores

CVSS v3 3.7
EPSS 0.0008
EPSS Percentile 24.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N

Classification

CWE
CWE-77
Status published

Affected Products (2)

gitlab/gitlab < 17.8.6
gitlab/gitlab

Timeline

Published Mar 27, 2025
Tracked Since Feb 18, 2026