Race condition in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2024-11222

 

Race condition in Gitlab Community Edition and GitLab Enterprise Edition - CVE-2024-11222

Published: September 11, 2026


Vulnerability identifier: #VU149013
CSH Severity: Low
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-11222
CWE-ID: CWE-362
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to perform actions in the context of another user\'s merge request commit.

The vulnerability exists due to a race condition in merge request pipeline creation when creating pipelines. A remote user can exploit the race condition to perform actions in the context of another user\'s merge request commit.

User interaction is required.


Affected software

Gitlab Community Edition
GitLab Enterprise Edition

How to mitigate CVE-2024-11222

Install security update from vendor's website.

Gitlab Community Edition - addressed in versions 19.1.8, 19.2.6, 19.3.2
GitLab Enterprise Edition - addressed in versions 19.1.8, 19.2.6, 19.3.2

External References

Related Security Bulletins