Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025

Deployment of AI agents? Learn to provide them before the hackers have contributed to your business

May 9, 2025

Initial Access brokers

May 9, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » GitLab releases patch for critical CI/CD pipeline vulnerability and 13 others
Global Security

GitLab releases patch for critical CI/CD pipeline vulnerability and 13 others

AdminBy AdminJuly 7, 2024No Comments2 Mins Read
CI/CD Pipeline Vulnerability
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


June 28, 2024Information hallSoftware Security / DevOps

CI/CD pipeline vulnerability

GitLab released security updates to address 14 security flaws, including one critical vulnerability that could be exploited to trigger continuous integration and continuous deployment (CI/CD) pipelines from any user.

Vulnerabilities affecting GitLab Community Edition (CE) and Enterprise Edition (EE) have been addressed in versions 17.1.1, 17.0.3, and 16.11.5.

The most serious of vulnerabilities CVE-2024-5655 (CVSS score: 9.6), which could allow an attacker to run a pipeline on behalf of another user under certain circumstances.

This affects the following CE and EE versions –

  • 17.1 to 17.1.1
  • 17.0 to 17.0.3 and
  • 15.8 to 16.11.5

GitLab said the fix introduces two critical changes, whereby GraphQL authentication using CI_JOB_TOKEN is disabled by default, and pipelines will no longer start automatically when a merge request is redirected after a previous target branch has been merged.

Cyber ​​security

Some other important bugs fixed in the latest release are listed below –

  • CVE-2024-4901 (CVSS Score: 8.7) – A stored XSS vulnerability can be imported from a project with malicious patch notes
  • CVE-2024-4994 (CVSS Score: 8.1) – CSRF attack on GitLab’s GraphQL API leading to arbitrary GraphQL mutations
  • CVE-2024-6323 (CVSS Score: 7.5) – Authorization error in the global search function that allows the leakage of sensitive information from a private repository in a public project
  • CVE-2024-2177 (CVSS Score: 6.8) – Crusader forgery vulnerability that allows an attacker to abuse the OAuth authentication flow via a crafted payload

Although there is no evidence of active use of the flaws, users are advised to apply patches to reduce potential threats.

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025

Deployment of AI agents? Learn to provide them before the hackers have contributed to your business

May 9, 2025

Initial Access brokers

May 9, 2025

Google unfolds on the AI ​​Defense device to detect scam in Chrome and Android

May 9, 2025

Chinese hackers operate SAP RCE LINK

May 9, 2025

38 000+ Friedomen Found that exploit SEO to steal the crypt -seed phrases

May 8, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025

Deployment of AI agents? Learn to provide them before the hackers have contributed to your business

May 9, 2025

Initial Access brokers

May 9, 2025

Google unfolds on the AI ​​Defense device to detect scam in Chrome and Android

May 9, 2025

Chinese hackers operate SAP RCE LINK

May 9, 2025

38 000+ Friedomen Found that exploit SEO to steal the crypt -seed phrases

May 8, 2025

Sonicwall Patches 3 flaws in SMA 100 devices, allowing attackers to run the code as a root

May 8, 2025

Qilin leads April 2025. Spike ransomware with 45 disorders using malware Netxloader

May 8, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Malicious NPM packages infect 3200+ users cursor with back, theft of credentials

May 9, 2025

Deployment of AI agents? Learn to provide them before the hackers have contributed to your business

May 9, 2025

Initial Access brokers

May 9, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.