An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a Maintainer to introduce malicious code.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/482813 | Exploit Issue Tracking |
https://hackerone.com/reports/2601569 | Permissions Required |
Configurations
Configuration 1 (hide)
|
History
08 Aug 2025, 01:16
Type | Values Removed | Values Added |
---|---|---|
References | () https://gitlab.com/gitlab-org/gitlab/-/issues/482813 - Exploit, Issue Tracking | |
References | () https://hackerone.com/reports/2601569 - Permissions Required | |
First Time |
Gitlab
Gitlab gitlab |
|
Summary |
|
|
CPE | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* |
13 Mar 2025, 06:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-13 06:15
Updated : 2025-08-08 01:16
NVD link : CVE-2024-8402
Mitre link : CVE-2024-8402
CVE.ORG link : CVE-2024-8402
JSON object : View
Products Affected
gitlab
- gitlab
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')