Medium severity6.5NVD Advisory· Published Sep 12, 2024· Updated Jun 17, 2026
CVE-2024-8311
CVE-2024-8311
Description
An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 17.2
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=17.2.0,<17.2.5
- (no CPE)range: >=17.2, <17.2.5 || >=17.3, <17.3.2
Patches
Vulnerability mechanics
References
2News mentions
1- GitLab Critical Patch Release: 17.3.2, 17.2.5, 17.1.7GitLab Security Releases · Sep 11, 2024