GPU VulnDB

Database/Control plane, storage & DevOps

GitLab CE/EE: pipeline creation race lets a developer act in the context of another user's merge request commit

CVSS 6.4CVE-2024-11222Control plane, storage & DevOpscurated

Impact

A race condition in pipeline creation could, under certain conditions, let a user with Developer access have actions run in the context of another user's merge request commit. For a self-hosted GitLab that builds and publishes the images, drivers and model artifacts a GPU fleet runs, that is a CI identity confusion in the pipeline that holds registry and deploy credentials. The advisory does not describe the preconditions in detail and the record notes user interaction is required, so treat this as a CI supply-chain integrity issue whose exploitability depends on local workflow rather than a straightforward remote takeover.

Who can reach it

An authenticated user with Developer access to the project, targeting a merge request; the record's vector indicates user interaction is required and attack complexity is high.

What to do

Upgrade self-managed GitLab to 19.1.8, 19.2.6 or 19.3.2 (all versions from 13.0 are affected) and restart the GitLab services. GitLab.com is already patched. This is an application upgrade, not fleet maintenance; review recent pipeline runs on merge requests if your runners hold privileged credentials.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.