VDB

CVE-2024-5655

CVE-2024-5655 PUBLISHED

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.

EPSS 1.74% · 82.9th percentile

Risk Scores

EPSS Score
1.74%
82.9th percentile

Affected Products

VendorProductVersions
Bitnamigitlab15.8.0, 17.0.0, 17.1.0
Bitnamigitlab15.8.0, 17.0.0, 17.1.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Jun 26, 2024 CVE Published
  • Jun 26, 2024 PoC Published
  • Jun 27, 2024 EPSS Score
  • Jun 28, 2024 PoC Published
  • Jun 28, 2024 PoC Published
  • Jun 28, 2024 PoC Published
  • Jun 30, 2024 PoC Published
  • Jul 3, 2024 PoC Published
  • Jul 11, 2024 PoC Published
  • Jul 19, 2024 EPSS Score
  • Aug 11, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›