VYPR
Unrated severityNVD Advisory· Published May 23, 2025· Updated May 27, 2025

User Interface (UI) Misrepresentation of Critical Information in GitLab

CVE-2024-9163

Description

A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs.

Affected products

2
  • GitLab Inc./GitLabv52 versions
    cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 12.1
    • (no CPE)range: >=12.1, <17.10.7 || >=17.11, <17.11.3 || >=18.0, <18.0.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

1