An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances.
2025-02-13T01:15:24.980
2025-08-06T18:49:23.593
Analyzed
CVSSv3.1: 9.6 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | gitlab | gitlab | < 17.5.0 | Yes |
| Application | gitlab | gitlab | < 17.5.0 | Yes |