Medium severity5.3NVD Advisory· Published Jun 12, 2025· Updated Jun 17, 2026
CVE-2024-9512
CVE-2024-9512
Description
An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync.
Affected products
5cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: <17.10.8
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: <17.10.8
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 0
- Range: <17.10.8, <17.11.4, <18.0.2
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/497748nvdBroken Link
- hackerone.com/reports/2683469nvdPermissions Required
News mentions
1- GitLab Patch Release: 18.0.2, 17.11.4, 17.10.8GitLab Security Releases · Jun 11, 2025