Medium severity6.4NVD Advisory· Published Jan 24, 2025· Updated Jun 17, 2026
CVE-2024-11931
CVE-2024-11931
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.0 prior to 17.6.4, from 17.7 prior to 17.7.3, and from 17.8 prior to 17.8.1. Under certain conditions, it may have been possible for users with developer role to exfiltrate protected CI variables via CI lint.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
30cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 17.0
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=17.0.0,<17.6.4
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=17.0.0,<17.6.4
- cpe:2.3:a:gitlab:gitlab:17.8.0:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:17.8.0:*:*:*:enterprise:*:*:*
- (no CPE)range: >=17.0 <17.6.4, >=17.7 <17.7.3, >=17.8 <17.8.1
- osv-coords24 versionspkg:apk/chainguard/gitlab-base-fips-17.6pkg:apk/chainguard/gitlab-base-fips-17.8pkg:apk/chainguard/gitlab-cng-fips-17.6pkg:apk/chainguard/gitlab-cng-fips-17.8pkg:apk/chainguard/gitlab-container-registry-fips-17.6pkg:apk/chainguard/gitlab-container-registry-fips-17.8pkg:apk/chainguard/gitlab-docker-machine-fips-17.8pkg:apk/chainguard/gitlab-elasticsearch-indexer-fips-17.6pkg:apk/chainguard/gitlab-elasticsearch-indexer-fips-17.8pkg:apk/chainguard/gitlab-logger-fips-17.6pkg:apk/chainguard/gitlab-logger-fips-17.8pkg:apk/chainguard/gitlab-runner-fips-17.8pkg:apk/chainguard/gitlab-runner-helper-compat-17.8pkg:apk/chainguard/gitlab-runner-helper-compat-fips-17.8pkg:apk/chainguard/gitlab-runner-helper-fips-17.8pkg:apk/chainguard/gitlab-runner-helper-oci-entrypoint-17.8pkg:apk/chainguard/gitlab-runner-helper-oci-entrypoint-fips-17.8pkg:apk/chainguard/gitlab-runner-oci-entrypoint-17.8pkg:apk/chainguard/gitlab-runner-oci-entrypoint-fips-17.8pkg:apk/chainguard/gitlab-shell-fips-17.6pkg:apk/chainguard/gitlab-shell-fips-17.8pkg:apk/chainguard/gitlab-toolbox-fips-17.6pkg:apk/chainguard/gitlab-toolbox-fips-17.8pkg:bitnami/gitlab
< 17.6.5-r0+ 23 more
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.8.2-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.8.2-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.8.2-r0
- (no CPE)range: < 17.8.3-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.8.2-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.8.2-r0
- (no CPE)range: < 17.8.3-r0
- (no CPE)range: < 17.8.3-r0
- (no CPE)range: < 17.8.3-r0
- (no CPE)range: < 17.8.3-r0
- (no CPE)range: < 17.8.3-r0
- (no CPE)range: < 17.8.3-r0
- (no CPE)range: < 17.8.3-r0
- (no CPE)range: < 17.8.3-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.8.2-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.8.2-r0
- (no CPE)range: >= 17.0.0, < 17.6.4
Patches
Vulnerability mechanics
References
2News mentions
1- GitLab Patch Release: 17.8.1, 17.7.3, 17.6.4GitLab Security Releases · Jan 22, 2025