An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitLab

Published: 2024-06-26T23:30:55.421Z

Updated: 2024-06-28T13:09:22.469Z

Reserved: 2024-06-05T16:02:36.421Z


Link: CVE-2024-5655

JSON object: View

cve-icon NVD Information

Status : Awaiting Analysis

Published: 2024-06-27T00:15:12.887

Modified: 2024-06-27T12:47:19.847


Link: CVE-2024-5655

JSON object: View

cve-icon Redhat Information

No data.

CWE