Unrated severityNVD Advisory· Published Jun 12, 2025· Updated Jun 12, 2025
Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab
CVE-2024-9512
Description
An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync.
Affected products
2cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 0
- (no CPE)range: <17.10.8, >=17.11 <17.11.4, >=18.0 <18.0.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- hackerone.com/reports/2683469mitretechnical-descriptionexploitpermissions-required
- gitlab.com/gitlab-org/gitlab/-/issues/497748mitreissue-trackingpermissions-required
News mentions
1- GitLab Patch Release: 18.0.2, 17.11.4, 17.10.8GitLab Security Releases · Jun 11, 2025