GitLab warnt vor kritischer Schwachstelle in der Pipeline-Ausführung

Teilen:

GitLab has released critical updates to address multiple vulnerabilities, the most severe of them (CVE-2024-6678) allowing an attacker to trigger pipelines as arbitrary users under certain conditions.

The release is for versions 17.3.2, 17.2.5, and 17.1.7 for both GitLab Community Edition (CE) and Enterprise Edition (EE), and patches a total of 18 security issues as part of the bi-monthly (scheduled) security updates.

With a critical severity score of 9.9, the CVE-2024-6678 vulnerability could enable an attacker to execute environment stop actions as the owner of the stop action job.

The severity of the flaw comes from its potential for remote exploitation, lack of user interaction, and the low privileges required for exploiting it.

GitLab warns that the issue affects CE/EE versions from 8.14 up to 17.1.7, versions from 17.2 prior to 17.2.5, and versions from 17.3 prior to 17.3.2.

We strongly recommend that all installations running a version affected by the issues described below are upgraded to the latest version as soon as possible. – GitLab

GitLab pipelines are automated workflows used to build, test, and deploy code, part of GitLab’s CI/CD (Continuous Integration/Continuous Delivery) system.

They are designed to streamline the software development process by automating repetitive tasks and ensuring that changes to the codebase are tested and deployed consistently.

GitLab addressed arbitrary pipeline execution vulnerabilities multiple times in recent months, including in July 2024, to fix CVE-2024-6385, in June 2024, to fix CVE-2024-5655, and in September 2023 to patch CVE-2023-5009, all rated critical.

The bulletin also lists four high-severity issues with scores between 6.7 – 8.5, that could potentially allow attackers to disrupt services, execute unauthorized commands, or compromise sensitive resources. The issues are summarized as follows:

  • CVE-2024-8640: Due to improper input filtering, attackers could inject commands into a connected Cube server via YAML configuration, potentially compromising data integrity. Impacts GitLab EE starting from 16.11.
  • CVE-2024-8635: Attackers could exploit a Server-Side Request Forgery (SSRF) vulnerability by crafting a custom Maven Dependency Proxy URL to make requests to internal resources, compromising internal infrastructure. Affects GitLab EE starting from 16.8.
  • CVE-2024-8124: Attackers could trigger a DoS attack by sending a large ‘glm_source’ parameter, overwhelming the system and making it unavailable. Impacts GitLab CE/EE starting from 16.4.
  • CVE-2024-8641: Attackers could exploit a CI_JOB_TOKEN to gain access to a victim’s GitLab session token, allowing them to hijack a session. Affects GitLab CE/EE starting from 13.7.

For update instructions, source code, and packages, check out GitLab’s official download portal. The latest GitLab Runner packages are available here.

Bill Toulas

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
6:56 pm, Juni 12, 2025
Wetter-Symbol 24°C
L: 23° | H: 25°
broken clouds
Luftfeuchtigkeit: 64 %
Druck: 1012 mb
Wind: 10 mph SW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:17 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
23° | 25°°C 0 mm 0% 9 mph 67 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
16° | 27°°C 1 mm 100% 7 mph 94 % 1019 mb 0 mm/h
Sa. Juni 14 10:00 pm
Wetter-Symbol
17° | 23°°C 1 mm 100% 13 mph 96 % 1019 mb 0 mm/h
So. Juni 15 10:00 pm
Wetter-Symbol
13° | 22°°C 0.46 mm 46% 10 mph 84 % 1025 mb 0 mm/h
Mo. Juni 16 10:00 pm
Wetter-Symbol
14° | 25°°C 0 mm 0% 7 mph 86 % 1027 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 9 mph 64 % 1012 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
20° | 23°°C 0 mm 0% 4 mph 67 % 1013 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
17° | 19°°C 0 mm 0% 3 mph 75 % 1015 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 3 mph 84 % 1017 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 7 mph 79 % 1018 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 7 mph 60 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 6 mph 41 % 1019 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 7 mph 40 % 1019 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€93,481.47
-0.76%
Ethereum(ETH)
€2,388.05
-2.61%
Fesseln(USDT)
€0.86
0.00%
XRP(XRP)
€1.94
-2.46%
Solana(SOL)
€138.29
-2.55%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.163810
-4.63%
Shiba Inu(SHIB)
€0.000011
-4.81%
Pepe(PEPE)
€0.000010
-5.08%
Peanut das Eichhörnchen(PNUT)
€0.236997
-5.02%
Nach oben scrollen