Intel

AIKIDO-2026-132296

gitlab-ce is vulnerable to Race Condition

Race ConditionCVE-2024-11222 Published 3 days ago

64

Medium Risk

This Affects:

OSgitlab-ce
13.0.0 - 19.1.7
Fixed in 19.1.8
19.2.0 - 19.2.5
Fixed in 19.2.6
19.3.0 - 19.3.1
Fixed in 19.3.2
Are you affected? Scan for Free

TL;DR

Merge request pipeline creation is subject to a race condition. A Developer can perform actions in the context of another user's merge request commit by winning that race. The fix serializes pipeline creation so the race can no longer switch commit context.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

gitlab-ce is vulnerable to Race Condition in versions 13.0.0 - 19.1.7, 19.2.0 - 19.2.5 and 19.3.0 - 19.3.1.

How to fix this

Upgrade the gitlab-ce library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform