CVE-2024-9512
Estado: AnalizadaMedia (5.9)—
An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
- Puntuación base: 5.9
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.25%
- Percentil entre todas las CVEs puntuadas: 15
- Fecha de la puntuación: 5/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-367
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-9512",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-9512",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-06-12T14:12:49.948999Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "cve@gitlab.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 1.6
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.9,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 3.6,
"exploitabilityScore": 2.2
}
]
},
"affected": [
{
"source": "cve@gitlab.com",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"
],
"repo": "git://git@gitlab.com:gitlab-org/gitlab.git",
"vendor": "GitLab",
"product": "GitLab",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "17.10.8",
"versionType": "semver"
},
{
"status": "affected",
"version": "17.11",
"lessThan": "17.11.4",
"versionType": "semver"
},
{
"status": "affected",
"version": "18.0",
"lessThan": "18.0.2",
"versionType": "semver"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-06-12T14:15:29.680",
"references": [
{
"url": "https://gitlab.com/gitlab-org/gitlab/-/issues/497748",
"tags": [
"Broken Link"
],
"source": "cve@gitlab.com"
},
{
"url": "https://hackerone.com/reports/2683469",
"tags": [
"Permissions Required"
],
"source": "cve@gitlab.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "cve@gitlab.com",
"description": [
{
"lang": "en",
"value": "CWE-367"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync."
},
{
"lang": "es",
"value": "Se ha detectado un problema en GitLab EE que afecta a todas las versiones anteriores a la 17.10.8, 17.11 anteriores a la 17.11.4 y 18.0 anteriores a la 18.0.2. Es posible que se haya clonado un repositorio privado en caso de una condición de ejecución cuando un nodo secundario no está sincronizado."
}
],
"lastModified": "2026-06-17T08:24:42.723",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61E74077-8E03-45E9-B5C0-50D1C5706D29",
"versionEndExcluding": "17.10.8"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE1C02F8-A03B-4647-8FA2-5C297D86BE26",
"versionEndExcluding": "17.10.8"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C804F9B0-8B23-4160-B24E-199411A81B95",
"versionEndExcluding": "17.11.4",
"versionStartIncluding": "17.11.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CEAA838C-7B3C-45AF-9D3D-BD5DE41E57BC",
"versionEndExcluding": "17.11.4",
"versionStartIncluding": "17.11.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7BD21B25-753E-48AB-B0D4-DFE90A135C04",
"versionEndExcluding": "18.0.2",
"versionStartIncluding": "18.0.0"
},
{
"criteria": "cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6224AE70-D146-4A3B-BD4E-2853891F24FA",
"versionEndExcluding": "18.0.2",
"versionStartIncluding": "18.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@gitlab.com"
}