CVE-2024-9512: Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab
An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync.
Other sources
GitLab has remediated an issue that, under certain conditions, could have allowed a successful attacker to clone a legitimate user’s private repository by sending a timed clone request when a secondary node is out of sync.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9512?
The severity of CVE-2024-9512 is classified as moderate, due to the potential for unauthorized access to private repositories under specific race conditions.
How do I fix CVE-2024-9512?
To mitigate CVE-2024-9512, upgrade GitLab EE to version 17.10.8 or later, 17.11.4 or later, or 18.0.2 or later.
What versions of GitLab EE are affected by CVE-2024-9512?
CVE-2024-9512 affects GitLab EE versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2.
What are the potential risks of CVE-2024-9512?
The risks associated with CVE-2024-9512 include the possibility of unauthorized cloning of private repositories under specific conditions.
Is there a workaround for CVE-2024-9512 if I cannot upgrade?
There is no documented workaround for CVE-2024-9512, so upgrading to a patched version is the recommended action.