VDB

CVE-2024-8970

CVE-2024-8970 PUBLISHED

An issue was discovered in GitLab CE/EE affecting all versions starting from 11.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

EPSS 0.07% · 20.9th percentile

Risk Scores

EPSS Score
0.07%
20.9th percentile

Affected Products

VendorProductVersions
Bitnamigitlab17.4.0, 11.6.0, 17.3.0
Bitnamigitlab17.3.0, 17.4.0, 11.6.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Oct 9, 2024 CVE Published
  • Oct 12, 2024 EPSS Score
  • Oct 14, 2024 Coalition ESS Score
  • Oct 15, 2024 Coalition ESS Score
  • Oct 31, 2024 EPSS Score
  • Nov 19, 2024 EPSS Score
  • Dec 8, 2024 EPSS Score
  • Dec 14, 2024 Coalition ESS Score
  • Dec 27, 2024 EPSS Score
  • Jan 15, 2025 EPSS Score
  • Feb 3, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›