VDB
CVE-2024-8970
CVE-2024-8970
PUBLISHED
An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.
EPSS 0.07% · 20.9th percentile
Risk Scores
EPSS Score
0.07%
20.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 17.4.0, 11.6.0, 17.3.0 |
| Bitnami | gitlab | 17.3.0, 17.4.0, 11.6.0 |
Timeline
- Jan 21, 1970 Security Advisory
- Oct 9, 2024 CVE Published
- Oct 12, 2024 EPSS Score
- Oct 14, 2024 Coalition ESS Score
- Oct 15, 2024 Coalition ESS Score
- Oct 31, 2024 EPSS Score
- Nov 19, 2024 EPSS Score
- Dec 8, 2024 EPSS Score
- Dec 14, 2024 Coalition ESS Score
- Dec 27, 2024 EPSS Score
- Jan 15, 2025 EPSS Score
- Feb 3, 2025 EPSS Score