VDB
CVE-2024-8640
CVE-2024-8640
PUBLISHED
An issue has been discovered in GitLab EE affecting all versions starting from 16.11 prior to 17.1.7, from 17.2 prior to 17.2.5, and from 17.3 prior to 17.3.2. Due to incomplete input filtering, it was possible to inject commands into a connected Cube server.
EPSS 0.30% · 53.8th percentile
Risk Scores
EPSS Score
0.30%
53.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 16.11.0, 17.2.0, 17.3.0 |
| Bitnami | gitlab | 16.11.0, 17.3.0, 17.2.0 |
Timeline
- Jan 21, 1970 Security Advisory
- Sep 11, 2024 CVE Published
- Sep 12, 2024 PoC Published
- Sep 13, 2024 EPSS Score
- Sep 13, 2024 PoC Published
- Sep 15, 2024 CVE Updated
- Oct 3, 2024 EPSS Score
- Oct 5, 2024 Coalition ESS Score
- Oct 23, 2024 EPSS Score
- Nov 11, 2024 EPSS Score
- Dec 2, 2024 EPSS Score
- Dec 22, 2024 EPSS Score