An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a Maintainer to introduce malicious code.
History

Thu, 13 Mar 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Mar 2025 06:00:00 +0000

Type Values Removed Values Added
Description An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a Maintainer to introduce malicious code.
Title Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-77
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2025-03-13T05:56:29.590Z

Updated: 2025-03-13T19:38:58.363Z

Reserved: 2024-09-03T23:01:56.416Z

Link: CVE-2024-8402

cve-icon Vulnrichment

Updated: 2025-03-13T19:38:55.103Z

cve-icon NVD

Status : Received

Published: 2025-03-13T06:15:36.117

Modified: 2025-03-13T06:15:36.117

Link: CVE-2024-8402

cve-icon Redhat

No data.