Critical severity9.6NVD Advisory· Published Jul 11, 2024· Updated Jun 17, 2026
CVE-2024-6385
CVE-2024-6385
Description
An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 15.8
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=15.8.0,<16.11.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=15.8.0,<16.11.6
- Range: 15.8 - 16.11.5, 17.0 - 17.0.3, 17.1 - 17.1.1
- osv-coords4 versionspkg:bitnami/gitlabpkg:deb/ubuntu/[email protected]?arch=source&distro=noblepkg:deb/ubuntu/[email protected]?arch=source&distro=oracularpkg:deb/ubuntu/[email protected]+dfsg-5?arch=source&distro=esm-apps/xenial
>= 15.8.0, < 16.11.6+ 3 more
- (no CPE)range: >= 15.8.0, < 16.11.6
- (no CPE)range: >= 0
- (no CPE)range: >= 0
- (no CPE)range: >= 0
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/469217nvdBroken Link
- hackerone.com/reports/2578672nvdPermissions Required
News mentions
2- GitLab Patch Release: 17.7.1, 17.6.3, 17.5.5GitLab Security Releases · Jan 8, 2025
- GitLab Critical Patch Release: 17.1.2, 17.0.4, 16.11.6GitLab Security Releases · Jul 10, 2024