CVE-2024-9163: User Interface (UI) Misrepresentation of Critical Information in GitLab
A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9163?
CVE-2024-9163 has been classified as a high severity vulnerability due to its exploitation potential allowing attackers to confuse branch names in confidential merge requests.
How do I fix CVE-2024-9163?
To fix CVE-2024-9163, upgrade your GitLab CE/EE to version 17.10.7, 17.11.3, or 18.0.1 or later.
Which versions of GitLab are affected by CVE-2024-9163?
CVE-2024-9163 affects all GitLab CE/EE versions from 12.1 up to the specified safe versions, including 17.10.6 and earlier, 17.11.2 and earlier, and 18.0.0.
What type of vulnerability is CVE-2024-9163?
CVE-2024-9163 is classified as a business logic error that can lead to branch name confusion in confidential merge requests.
Can CVE-2024-9163 be exploited remotely?
Yes, CVE-2024-9163 can be exploited remotely by attackers to manipulate branch names in confidential merge requests.