PoC Index

CVE-2024-8402

HIGH 7.4EPSS 0.2%

An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a Maintainer to introduce malicious code.

CVSS v3.1
7.4 HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:N
CVSS v3.1
3.7 LOWCVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS
0.24% chance of exploitation in the next 30 days, 14th percentile
Published
2025-03-13

Proof-of-concept exploits (1)

References

Related