First published: Thu Mar 13 2025(Updated: )
An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a Maintainer to introduce malicious code.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab Enterprise Edition | >=17.2<17.7.7>=17.8<17.8.5>=17.9<17.9.2 |
Upgrade to versions 17.7.7, 17.8.5, 17.9.2.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-8402 is classified as a high severity vulnerability due to its potential impact on authentication workflows.
To resolve CVE-2024-8402, upgrade GitLab EE to version 17.7.7, 17.8.5, or 17.9.2 or later.
CVE-2024-8402 affects GitLab EE versions from 17.2 up to but not including 17.7.7, from 17.8 up to but not including 17.8.5, and from 17.9 up to but not including 17.9.2.
CVE-2024-8402 is an input validation issue specifically related to the Google Cloud IAM integration feature.
Yes, CVE-2024-8402 could potentially enable unauthorized access through compromised authentication mechanisms.