GitLab Issues Critical CI/CD Pipeline Vulnerability Patch Alongside 13 Additional Updates

Tech & AI | June 29, 2024, 8:34 a.m.

GitLab has recently released security updates to address 14 vulnerabilities, including a critical flaw that could be exploited to run CI/CD pipelines as any user. The vulnerabilities impact GitLab Community Edition and Enterprise Edition, with the most severe being CVE-2024-5655, which allows a malicious actor to trigger pipelines as another user. The updates in versions 17.1.1, 17.0.3, and 16.11.5 also introduce breaking changes to enhance security measures. Some of the other significant flaws fixed include stored XSS vulnerabilities, CSRF attacks, an authorization flaw in the global search feature, and a cross window forgery vulnerability. While there is no evidence of active exploitation, users are advised to apply the patches to safeguard against potential threats. This latest release underscores the ongoing commitment of GitLab to prioritize security and protect its users from cyber threats.