GitLab released security updates 17.3.2, 17.2.5, and 17.1.7 for self-managed Community Edition and Enterprise Edition instances, fixing 18 vulnerabilities including a critical issue tracked as CVE-2024-6678 with a CVSS score of 9.9. The flaw could let an attacker trigger a CI/CD pipeline as an arbitrary user and perform a stop action under certain conditions. GitLab said GitLab.com is already running the patched version and GitLab Dedicated customers do not need to take action.
The release also fixes several high-severity bugs, including command injection into a connected Cube server via YAML configuration (CVE-2024-8640), server-side request forgery through Maven Dependency Proxy requests to internal resources (CVE-2024-8635), and a denial-of-service condition caused by a crafted POST request or large glm_source parameter (CVE-2024-8124). Additional medium-severity patches address token and session abuse, permission bypasses, information disclosure, and open redirects that could contribute to account takeover through broken OAuth flows, and GitLab urged all self-managed administrators to upgrade immediately.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
GitLab released versions 17.3.2, 17.2.5, and 17.1.7 for self-managed Community Edition and Enterprise Edition installations to fix 18 vulnerabilities. The update addressed the critical CVE-2024-6678 and multiple high-severity flaws including command injection, SSRF, and denial-of-service issues; GitLab.com and GitLab Dedicated were already protected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.