Vulnerability in GitLab Allowing Pipeline Jobs to Run Under Another User
Corrective updates for the collaborative development platform - GitLab 17.1.1, 17.0.3, 16.11.5, 16.10.8, 16.9.9, 16.8.8, 16.7.8, and 16.6.8 have been released, addressing 14 vulnerabilities. One of the issues (CVE-2024-5655) that appears starting from GitLab version 15.8 has been assigned a critical severity level. This vulnerability allows for the execution of continuous integration pipeline jobs under any user. Performing one’s own job […]
