CVE-2024-9512: GitLab

Medium severity, CVSS 5.9. EPSS: 0.2% chance of exploitation in the next 30 days.

An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private repository to be cloned in case of race condition when a secondary node is out of sync.

Affected products

  • GitLab GitLab: before 17.10.8 (fixed in 17.10.8); from 17.11.0, before 17.11.4 (fixed in 17.11.4); from 18.0.0, before 18.0.2 (fixed in 18.0.2)

Published 2025-06-12. Last modified 2026-06-17.