CVE-2024-8311 - GitLab Pipeline Execution Policy Variable Overwrite Protection Bypass

2 months ago 30
ARTICLE AD BOX
CVE ID : CVE-2024-8311
Published : Sept. 12, 2024, 7:15 p.m. | 24 minutes ago
Description : An issue was discovered with pipeline execution policies in GitLab EE affecting all versions from 17.2 prior to 17.2.5, 17.3 prior to 17.3.2 which allows authenticated users to bypass variable overwrite protection via inclusion of a CI/CD template.
Severity: 6.5 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Read Entire Article