CVE-2024-9773: Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab
An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious code to the CLI commands shown in the UI.
Other sources
An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.9.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious code to the CLI commands shown in the UI. This is a low severity issue (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N, 3.7). It is now mitigated in the latest release and is assigned CVE-2024-9773.
— GitLab
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-9773?
CVE-2024-9773 is classified as a high-severity vulnerability due to its potential impact on GitLab EE installations.
How do I fix CVE-2024-9773?
To address CVE-2024-9773, update your GitLab EE instance to the latest version 17.10.1 or apply the necessary patches provided by GitLab.
Which versions of GitLab EE are affected by CVE-2024-9773?
CVE-2024-9773 affects all GitLab EE versions from 14.9 before 17.8.6, from 17.9 before 17.8.3, and from 17.10 before 17.10.1.
What type of issue is CVE-2024-9773?
CVE-2024-9773 is an input validation issue specifically affecting the Harbor registry integration in GitLab EE.
Can a maintainer exploit CVE-2024-9773?
Yes, CVE-2024-9773 allows a maintainer to exploit the input validation vulnerability, potentially compromising the integrity of the registry.