[subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A critical security vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE), tracked as CVE-2024-9164, has been discovered, allowing unauthorized users to trigger Continuous Integration/Continuous Delivery (CI/CD) pipelines on any branch of a repository. This flaw enables attackers to bypass branch protections, potentially leading to unauthorized code execution or access to sensitive information. GitLab EE versions starting from and are affected. GitLab users are strongly advised to upgrade to versions where the issue has been patched. Several other vulnerabilities have been addressed, including high-severity flaws that enable user impersonation and server-side request forgery (SSRF). Users should promptly upgrade to the fixed ensure their systems remain secure.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
A critical security vulnerability in GitLab Community Edition (CE) and Enterprise Edition (EE), tracked as CVE-2024-9164, has been discovered, allowing unauthorized users to trigger Continuous Integration/Continuous Delivery (CI/CD) pipelines on any branch of a repository. This flaw enables attackers to bypass branch protections, potentially leading to unauthorized code execution or access to sensitive information. GitLab EE versions starting from and are affected. GitLab users are strongly advised to upgrade to versions where the issue has been patched. Several other vulnerabilities have been addressed, including high-severity flaws that enable user impersonation and server-side request forgery (SSRF). Users should promptly upgrade to the fixed ensure their systems remain secure.[emaillocker id="1283"]
- CVE-2024-9164: A critical vulnerability allowing unauthorized users to trigger CI/CD pipelines on any repository branch, bypassing branch protections and potentially enabling code execution or access to sensitive data.
- CVE-2024-8970: A high-severity arbitrary user impersonation flaw, allowing attackers to trigger pipelines as another user, potentially leading to unauthorized actions within the system.
- CVE-2024-8977: A high-severity Server-Side Request Forgery (SSRF) vulnerability in the Analytics Dashboard, exposing instances to SSRF attacks that could lead to data exfiltration or system compromise.
- CVE-2024-9631: A high-severity vulnerability causing significant performance degradation when viewing diffs of merger requests with conflicts, potentially impacting the availability and usability of the service.
- CVE-2024-6530: A high-severity HTML injection flaw on the OAuth authorization page, allowing cross-site scripting (XSS) attacks during the OAuth authorization process, posing risks to user credentials and session data.
- CVE-2024-9623: A medium-severity issue where deploys can push to archived repositories, which could be abused for unauthorized actions on code repositories.
- CVE-2024-5005: A medium-severity vulnerability that allows guest users to disclose project templates via API, potentially exposing sensitive project details to unauthorized users.
- CVE-2024-9596: A low-severity vulnerability allowing GitLab instance version disclosure to unauthorized users, potentially enabling attackers to tailor exploits to the version of GitLab in use.
- CVE-2024-6678: A critical vulnerability addressed earlier this year, also related to arbitrary pipeline execution, allowing attackers to trigger pipelines without proper authorization.
- CVE-2024-6385: A critical flaw identified in July, enabling unauthorized users to execute pipelines on restricted branches, with the risk of executing arbitrary code.
- CVE-2024-5655: A critical vulnerability discovered in June, concerning the improper execution of CI/CD pipelines, exposing GitLab instances to arbitrary code execution risks.
RECOMMENDATION:
We strongly recommend you update GitLab Community Edition (CE) and Enterprise Edition (EE) to one of these versions: 17.4.2, 17.3.5, 17.2.9.
REFERENCES:
The following reports contain further technical details:
https://www.bleepingcomputer.com/news/security/gitlab-warns-of-critical-arbitrary-branch-pipeline-execution-flaw/
[/emaillocker]