GitLab released security updates 17.3.2, 17.2.5, and 17.1.7 for self-managed Community Edition and Enterprise Edition to fix multiple vulnerabilities, including the critical CVE-2024-6678. GitLab said the flaw can let an attacker trigger a pipeline as an arbitrary user under certain circumstances and assigned it a CVSS 9.9, urging customers to upgrade immediately. GitLab.com had already been patched, and GitLab Dedicated customers did not need to take action.
The patch bundle also addressed three high-severity issues and numerous medium- and low-severity flaws affecting pipelines, Product Analytics, Dependency Proxy, OAuth flows, CI/CD variables, repository mirroring, and access controls. A separate CVE entry for CVE-2024-8640 was listed without public details, while GitLab also noted one issue involving arbitrary unclaimed provider identities had not yet received a CVE at the time of publication.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
On September 11, 2024, GitLab released versions 17.3.2, 17.2.5, and 17.1.7 for GitLab CE/EE and urged self-managed customers to upgrade immediately. The release fixed multiple vulnerabilities, including critical CVE-2024-6678, which could allow an attacker to trigger a pipeline as an arbitrary user under certain circumstances.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.