Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-7102


An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances.


Published

2025-02-13T01:15:24.980

Last Modified

2025-08-06T18:49:23.593

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.6 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-250
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 17.5.0 Yes
Application gitlab gitlab < 17.5.0 Yes

References