CVE-2024-8970
CVE-2024-8970 is a GitLab CE/EE vulnerability that allows an attacker to trigger a pipeline as another user. This issue impacts versions from 11.6 before 17.2.9, 17.3 before 17.3.5, and 17.4 before 17.4.2. While the CVSS score is 0, indicating no severity, the SVRS score of 30 suggests a low-level risk. This vulnerability could allow unauthorized users to execute code or access sensitive data within the pipeline context of another user. The vulnerability is significant because it compromises user identity and potentially allows for malicious activities under the guise of a legitimate user. Prompt patching is advisable to mitigate the risk of unauthorized pipeline triggers and potential data breaches, even though the vulnerability is currently considered low-risk.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.