VDB
CVE-2024-8402
CVE-2024-8402
PUBLISHED
CVSS 7.400000095367432 HIGH
An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a Maintainer to introduce malicious code.
EPSS 0.24% · 13.1th percentile
Risk Scores
CVSS 3.1
7.400000095367432
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
EPSS Score
0.24%
13.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 17.2.0 |
| Bitnami | gitlab | 17.2.0 |
Timeline
- Jan 21, 1970 Security Advisory
- Mar 12, 2025 CVE Published
- Mar 13, 2025 Coalition ESS Score
- Mar 14, 2025 EPSS Score
- Mar 27, 2025 Coalition ESS Score
- Mar 28, 2025 EPSS Score
- Mar 29, 2025 Coalition ESS Score
- Apr 11, 2025 EPSS Score
- Apr 24, 2025 EPSS Score
- May 8, 2025 EPSS Score
- May 22, 2025 EPSS Score
- Jun 5, 2025 EPSS Score