An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync.
Metrics
Affected Vendors & Products
References
History
Thu, 12 Jun 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 12 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync. | |
Title | Time-of-check Time-of-use (TOCTOU) Race Condition in GitLab | |
First Time appeared |
Gitlab
Gitlab gitlab |
|
Weaknesses | CWE-367 | |
CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
Vendors & Products |
Gitlab
Gitlab gitlab |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitLab
Published: 2025-06-12T14:02:55.123Z
Updated: 2025-06-12T14:13:37.117Z
Reserved: 2024-10-04T06:02:21.940Z
Link: CVE-2024-9512

Updated: 2025-06-12T14:13:23.946Z

Status : Awaiting Analysis
Published: 2025-06-12T14:15:29.680
Modified: 2025-06-12T16:06:20.180
Link: CVE-2024-9512

No data.