InsighthubNews
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
Reading: GitLab Fixes Critical Flaw That Allowed Unauthorized Pipeline Job Execution
Share
Font ResizerAa
InsighthubNewsInsighthubNews
Search
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
© 2024 All Rights Reserved | Powered by Insighthub News
InsighthubNews > Technology > GitLab Fixes Critical Flaw That Allowed Unauthorized Pipeline Job Execution
Technology

GitLab Fixes Critical Flaw That Allowed Unauthorized Pipeline Job Execution

September 13, 2024 2 Min Read
Share
GitLab
SHARE

GitLab released a security update on Wednesday to address 17 security vulnerabilities, including a critical flaw that could allow attackers to run pipeline jobs as any user.

The issue, tracked as CVE-2024-6678, has a CVSS score of 9.9 out of a maximum of 10.0.

“An issue was discovered in GitLab CE/EE affecting all versions from 8.14 before 17.1.7, 17.2 before 17.2.5, and 17.3 before 17.3.2. This issue could allow an attacker to trigger pipelines as any user under certain circumstances,” the company said in its alert.

The vulnerability, along with three high severity, 11 medium severity, and two low severity bugs, have been fixed in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 17.3.2, 17.2.5, and 17.1.7.

It’s worth noting that CVE-2024-6678 is the fourth vulnerability GitLab has fixed in the past year, following CVE-2023-5009 (CVSS Score: 9.6), CVE-2024-5655 (CVSS Score: 9.6), and CVE-2024-6385 (CVSS Score: 9.6).

While there is no evidence that the flaws are being actively exploited in the wild, users are advised to apply the patch as soon as possible to mitigate any potential threat.

In early May of this year, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) revealed that a critical vulnerability in GitLab (CVE-2023-7028, CVSS score: 10.0) was being exploited in the wild.

See also  Is there a way to slow down fast fashion? Lawmakers are trying
Share This Article
Twitter Copy Link
Previous Article Silent Hill: Town Fall publisher Annapurna resigns entirely from staff Silent Hill: Town Fall publisher Annapurna resigns entirely from staff
Next Article President Trump calls for repeal of overtime tax at Tucson rally President Trump calls for repeal of overtime tax at Tucson rally
Leave a comment Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest News

The Solution is Cyber ​​Hygiene

The Solution is Cyber ​​Hygiene

Cybersecurity in healthcare has never been more urgent. As the…

September 19, 2024
mm

Enterprise LLM API: A top choice for powering LLM applications in 2024

Some big recent news stories have escalated the race for…

September 19, 2024
Authentication Bypass

GitLab fixes critical SAML authentication bypass vulnerability in CE and EE editions

GitLab has released a patch to address a critical flaw…

September 19, 2024
Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

Chinese engineer indicted in US for years of cyberespionage targeting NASA and military

A Chinese national has been indicted in the United States…

September 19, 2024
IoT Botnet

New “Raptor Train” IoT Botnet Compromises Over 200,000 Devices Worldwide

Cybersecurity researchers have discovered a never-before-seen botnet made up of…

September 18, 2024

You Might Also Like

HTTP Headers for Credential Theft
Technology

Cybercriminals exploit HTTP headers to steal credentials through mass phishing attacks

7 Min Read
Cloud Appliance Vulnerability
Technology

Ivanti warns of campaign exploiting newly patched cloud appliance vulnerability

2 Min Read
Wildfires in southern Brazil kill two, raise alert levels in dozens of cities
World News

Wildfires in southern Brazil kill two, raise alert levels in dozens of cities

2 Min Read
mm
Technology

How AI can help map the universe

9 Min Read
InsighthubNews
InsighthubNews

Welcome to InsighthubNews, your reliable source for the latest updates and in-depth insights from around the globe. We are dedicated to bringing you up-to-the-minute news and analysis on the most pressing issues and developments shaping the world today.

  • Home
  • Celebrity
  • Environment
  • Business
  • Crypto
  • Home
  • World News
  • Politics
  • Celebrity
  • Environment
  • Business
  • Technology
  • Crypto
  • Sports
  • Gaming
  • World News
  • Politics
  • Technology
  • Sports
  • Gaming
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service
  • About us
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms of Service

© 2024 All Rights Reserved | Powered by Insighthub News

Welcome Back!

Sign in to your account

Lost your password?