An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious code to the CLI commands shown in the UI.
History

Thu, 27 Mar 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Mar 2025 12:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious code to the CLI commands shown in the UI.
Title Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab
First Time appeared Gitlab
Gitlab gitlab
Weaknesses CWE-77
CPEs cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*
Vendors & Products Gitlab
Gitlab gitlab
References
Metrics cvssV3_1

{'score': 3.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published: 2025-03-27T12:31:27.475Z

Updated: 2025-03-27T13:07:40.267Z

Reserved: 2024-10-09T21:01:41.384Z

Link: CVE-2024-9773

cve-icon Vulnrichment

Updated: 2025-03-27T13:07:36.401Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-03-27T13:15:35.523

Modified: 2025-03-27T16:45:12.210

Link: CVE-2024-9773

cve-icon Redhat

No data.