Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-7110


An issue was discovered in GitLab EE affecting all versions starting 17.0 to 17.1.6, 17.2 prior to 17.2.4, and 17.3 prior to 17.3.1 allows an attacker to execute arbitrary command in a victim's pipeline through prompt injection.


Published

2024-08-22T16:15:10.627

Last Modified

2024-09-11T16:52:37.847

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.4 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-77
  • Type: Primary
    CWE-77

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 17.1.6 Yes
Application gitlab gitlab < 17.2.4 Yes
Application gitlab gitlab < 17.3.1 Yes
Application gitlab gitlab < 17.1.6 Yes
Application gitlab gitlab < 17.2.4 Yes
Application gitlab gitlab < 17.3.1 Yes

References