MEDIUM
Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab
Published Aug 22, 2024
6.4
MEDIUMCVSS 3.1
EPSS 0.36%
Description
An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1 allows an attacker to execute arbitrary command in a victim's pipeline through prompt injection.
Affected products
-
Affected
- ≥ 17.1, < 17.1.6
- ≥ 17.2, < 17.2.4
- ≥ 17.3, < 17.3.1
Configuration 1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 17.3.1, 17.2.4, 17.1.6 or above.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-48089 Advisory
- https://gitlab.com/gitlab-org/gitlab/-/issues/472603 issue-trackingpermissions-requiredThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-48089 | Advisory | |
| https://gitlab.com/gitlab-org/gitlab/-/issues/472603 | issue-trackingpermissions-requiredThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Aug 22, 2024
Updated Sep 17, 2024
Reserved Jul 25, 2024
Link CVE-2024-7110
CISA Vulnrichment
Updated Aug 22, 2024
Red Hat
No data
GitHub
No data