About the Vulnerability
Introduction
GitLab is an open-source project for repository management systems, using Git as the code management tool, based on which this Web service is built.
Summary
On October 10, 2024, Sangfor FarSight Labs received notification that a GitLab component contains information of Permission Bypass Vulnerability (CVE-2024-9164), classified as Critical in threat level.
There is a high-risk vulnerability in GitLab EE that allows low-privileged attackers to run pipelines on arbitrary branches, leading to the execution of malicious code and the leakage of sensitive information.
Affected Versions
12.5 ≤ GitLab EE < 17.2.9
17.3 ≤ GitLab EE < 17.3.5
17.4 ≤ GitLab EE < 17.4.2
Solutions
Remediation Solutions
Check the System Version
You can directly enter GitLab server address/help: https://your.gitlab.com/help
The information of GitLab’s version will be displayed on the interface.
Official Solution
Affected users are strongly advised to update the GitLab to the latest version(17.4.2, 17.3.5, 17.2.9 or versions above).
Download link: https://about.gitlab.com/update
Sangfor Solutions
Risky Assets Detection
Support is provided for the proactive detection of GitLab; and it is capable of batch identifying the affected asset conditions of this event in business scenarios. Related products are as follows:
[Sangfor CWPP] has released a detection scheme with Fingerprint ID: 0006687.
[Sangfor Host Security] has released a detection scheme with Fingerprint ID: 0006687.
Vulnerability Proactive Detection
Support is provided for proactive detection of GitLab EE Permission Bypass Vulnerability (CVE-2024-9164); and it is capable of quickly batch identifying whether there are vulnerability risks in business scenarios. Related products are as follows:
[Sangfor Host Security] is expected to release a detection scheme on October 13, 2024, with Rule ID: SF-0005-21020.
[Sangfor Cyber Guardian MDR] is expected to release a detection scheme on October 17, 2024, with Rule ID: SF-0005-21020.
[Sangfor Omni-Command] is expected to release a detection scheme on October 13, 2024(requiring Host Security component capabilities), with Rule ID: SF-0005-21020.
Timeline
On October 10, 2024, Sangfor FarSight Labs received notification of GitLab EE Permission Bypass vulnerability.
On October10, 2024, Sangfor FarSight Labs released a vulnerability alert.
References
https://about.gitlab.com/releases/2024/10/09/patch-release-gitlab-17- 4-2-released/