CVE-2024-8402: Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab
An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a Maintainer to introduce malicious code.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-8402?
CVE-2024-8402 is classified as a high severity vulnerability due to its potential impact on authentication workflows.
How do I fix CVE-2024-8402?
To resolve CVE-2024-8402, upgrade GitLab EE to version 17.7.7, 17.8.5, or 17.9.2 or later.
What versions of GitLab EE are affected by CVE-2024-8402?
CVE-2024-8402 affects GitLab EE versions from 17.2 up to but not including 17.7.7, from 17.8 up to but not including 17.8.5, and from 17.9 up to but not including 17.9.2.
What type of issue is CVE-2024-8402?
CVE-2024-8402 is an input validation issue specifically related to the Google Cloud IAM integration feature.
Can CVE-2024-8402 allow unauthorized access?
Yes, CVE-2024-8402 could potentially enable unauthorized access through compromised authentication mechanisms.