An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Gitaly allows injection of command-line flags. This sometimes leads to privilege escalation or remote code execution.
2023-04-16T00:15:07.227
2025-02-06T17:15:11.077
Modified
CVSSv3.1: 6.5 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | gitlab | gitlab | < 11.11.8 | Yes |
| Application | gitlab | gitlab | < 11.11.8 | Yes |
| Application | gitlab | gitlab | < 12.0.6 | Yes |
| Application | gitlab | gitlab | < 12.0.6 | Yes |
| Application | gitlab | gitlab | < 12.1.6 | Yes |
| Application | gitlab | gitlab | < 12.1.6 | Yes |