First published: Thu Mar 27 2025(Updated: )
An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious code to the CLI commands shown in the UI.
Credit: cve@gitlab.com
Affected Software | Affected Version | How to fix |
---|---|---|
GitLab Enterprise Edition | >14.9<17.8.6>17.9<17.8.3>17.10<17.10.1 |
Upgrade to versions 17.8.6, 17.9.3, 17.10.1 or above.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-9773 is classified as a high-severity vulnerability due to its potential impact on GitLab EE installations.
To address CVE-2024-9773, update your GitLab EE instance to the latest version 17.10.1 or apply the necessary patches provided by GitLab.
CVE-2024-9773 affects all GitLab EE versions from 14.9 before 17.8.6, from 17.9 before 17.8.3, and from 17.10 before 17.10.1.
CVE-2024-9773 is an input validation issue specifically affecting the Harbor registry integration in GitLab EE.
Yes, CVE-2024-9773 allows a maintainer to exploit the input validation vulnerability, potentially compromising the integrity of the registry.