VDB

CVE-2024-6385

CVE-2024-6385 PUBLISHED

An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

EPSS 1.13% · 78.7th percentile

Risk Scores

EPSS Score
1.13%
78.7th percentile

Affected Products

VendorProductVersions
Bitnamigitlab15.8.0, 17.1.0, 17.0.0
Bitnamigitlab15.8.0, 17.1.0, 17.0.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Jul 10, 2024 CVE Published
  • Jul 11, 2024 EPSS Score
  • Aug 2, 2024 EPSS Score
  • Aug 24, 2024 EPSS Score
  • Sep 15, 2024 EPSS Score
  • Oct 5, 2024 Coalition ESS Score
  • Oct 7, 2024 EPSS Score
  • Oct 29, 2024 EPSS Score
  • Nov 20, 2024 EPSS Score
  • Dec 13, 2024 EPSS Score
  • Dec 14, 2024 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›