VDB
CVE-2024-9163
CVE-2024-9163
PUBLISHED
A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs.
EPSS 0.05% · 17.1th percentile
Risk Scores
EPSS Score
0.05%
17.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | gitlab | 12.1.0, 18.0.0 |
| Bitnami | gitlab | 12.1.0, 18.0.0 |
Timeline
- Jan 21, 1970 Security Advisory
- May 21, 2025 CVE Published
- May 22, 2025 CVE Updated
- May 24, 2025 EPSS Score
- May 27, 2025 PoC Published
- Jun 2, 2025 Coalition ESS Score
- Jun 4, 2025 EPSS Score
- Jun 15, 2025 EPSS Score
- Jun 26, 2025 EPSS Score
- Jul 7, 2025 EPSS Score
- Jul 18, 2025 EPSS Score
- Jul 29, 2025 EPSS Score