GitLab issued several security patch releases for Community Edition and Enterprise Edition to fix vulnerabilities affecting self-managed deployments, including two critical pipeline impersonation flaws that could let an attacker run CI/CD pipeline jobs as another user. The issues were tracked as CVE-2024-5655 and CVE-2024-6385, with the latter included alongside fixes for group URL modification, deploy token creation, package registry manifest confusion, group member banning, and GitLab Pages subdomain takeover. GitLab said GitLab.com and GitLab Dedicated were already running patched versions and reported no evidence of abuse of CVE-2024-5655 on GitLab-managed platforms.
Subsequent patch releases addressed additional high- and medium-severity weaknesses, including stored cross-site scripting in Asciidoctor rendering (CVE-2025-0314), CI/CD variable exfiltration through CI lint (CVE-2024-11931), denial of service via cyclic epic references (CVE-2024-6324), access token exposure in logs, unauthorized issue status changes in public projects, and an Instance SAML configuration flaw that could expose internal projects or groups. GitLab also changed importer behavior after earlier importer-related problems, adding post-import mapping and user acceptance controls, and warned self-managed administrators using Direct Transfer, GitHub, Bitbucket Server, or Gitea importers to disable those features until upgraded.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
On January 22, 2025, GitLab released versions 17.8.1, 17.7.3, and 17.6.4 to fix three vulnerabilities: stored XSS in Asciidoctor rendering, CI/CD variable exfiltration via CI lint under certain conditions, and denial of service from cyclic epic references. GitLab said GitLab.com was already patched and GitLab Dedicated customers did not need to take action.
GitLab published CVE-2024-6324 on January 9, 2025, describing a medium-severity denial-of-service vulnerability caused by inefficient algorithmic complexity through cyclic references between epics. The CVE record credits researcher xorz and lists affected GitLab CE/EE version ranges.
On January 8, 2025, GitLab released versions 17.7.1, 17.6.3, and 17.5.5 to fix multiple medium-severity issues, including access token exposure in logs, unauthorized issue status changes, an Instance SAML flaw, and denial of service via cyclic epic references. GitLab also changed importer behavior after earlier importer-related vulnerabilities and advised self-managed customers with certain importers enabled to disable them until upgrading.
On July 10, 2024, GitLab released versions 17.1.2, 17.0.4, and 16.11.6 to address six vulnerabilities, including critical flaw CVE-2024-6385 that could let an attacker run pipeline jobs as another user under certain circumstances. GitLab stated that GitLab.com and GitLab Dedicated were already running patched versions.
On June 26, 2024, GitLab released versions 17.1.1, 17.0.3, and 16.11.5 for Community Edition and Enterprise Edition to fix multiple vulnerabilities, including the critical pipeline impersonation flaw CVE-2024-5655. GitLab said GitLab.com was already patched and reported no evidence of abuse on GitLab-managed platforms.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
5 references tracked. Mallory keeps watching after this page renders.
cve.mitre.org
Open sourcedocs.gitlab.com
Open sourcedocs.gitlab.com
Open sourcedocs.gitlab.com
Open sourcedocs.gitlab.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.