Back

MEDIUM

Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab

Published Aug 22, 2024

Description

An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1 allows an attacker to execute arbitrary command in a victim's pipeline through prompt injection.

Affected products

Remediation

Vendor solution

Upgrade to versions 17.3.1, 17.2.4, 17.1.6 or above.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitLab
Published Aug 22, 2024
Updated Sep 17, 2024
Reserved Jul 25, 2024

CISA Vulnrichment

Updated Aug 22, 2024

NVD

Status Analyzed
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitLab
Published Aug 22, 2024
Updated Sep 17, 2024

GitHub

No data