VDB
CVE-2024-6385
CVE-2024-6385
PUBLISHED
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.
EPSS 1.13% · 78.7th percentile
Risk Scores
EPSS Score
1.13%
78.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 15.8.0, 17.1.0, 17.0.0 |
| Bitnami | gitlab | 15.8.0, 17.1.0, 17.0.0 |
Timeline
- Jan 21, 1970 Security Advisory
- Jul 10, 2024 CVE Published
- Jul 11, 2024 EPSS Score
- Aug 2, 2024 EPSS Score
- Aug 24, 2024 EPSS Score
- Sep 15, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
- Oct 7, 2024 EPSS Score
- Oct 29, 2024 EPSS Score
- Nov 20, 2024 EPSS Score
- Dec 13, 2024 EPSS Score
- Dec 14, 2024 Coalition ESS Score