GitLab’s October 2024 security alert described a critical vulnerability in GitLab Enterprise Edition (EE) that could let an attacker run CI pipelines on arbitrary branches. If branch protections were bypassed, the issue could lead to arbitrary code execution. The fixes listed at the time—17.2.9, 17.3.5, and 17.4.2—are historical branch releases, not recommended upgrade targets today. Self-managed administrators should identify their deployment and installed version, then follow GitLab’s current supported upgrade guidance.
What the GitLab CI/CD vulnerability allowed
Hackster.io reported that GitLab described an issue affecting GitLab EE that could allow pipelines to run on arbitrary branches. GitLab’s description, quoted in the report, said the issue affected versions “starting from 12.5 prior to 17.2.9, starting from 17.3, prior to 17.3.5, and starting from 17.4, prior to 17.4.2.” GitLab rated it critical with a CVSS 3.1 score of 9.6, according to the report. Hackster.io’s October 2024 report
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages | $22.99 | Buy on Amazon |
The risk was not merely that a pipeline might start on an unexpected branch: the report said arbitrary code execution could result if branch protections were bypassed. The vulnerability was disclosed through GitLab’s HackerOne bug-bounty program, according to Hackster. The report also discussed other release fixes, including a related issue affecting both Community Edition (CE) and EE; that does not change the scope of this arbitrary-branch issue, which it identifies as an EE vulnerability.
Which GitLab installations were affected
The reported affected ranges were limited to GitLab EE, across three release lines:
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
| GitLab EE release line | Affected versions reported in 2024 | Historical fix listed |
|---|---|---|
| 17.2 | Earlier than 17.2.9 | 17.2.9 |
| 17.3 | Earlier than 17.3.5 | 17.3.5 |
| 17.4 | Earlier than 17.4.2 | 17.4.2 |
For the 17.2 line, the quoted range begins at 12.5, so versions from 12.5 up to—but not including—17.2.9 were included. The report specifies the 17.3 and 17.4 ranges as beginning at those respective major-minor versions and ending before the listed fix. It said GitLab.com and GitLab Dedicated were not affected by this advisory; the urgent patch recommendation was for self-managed installations running affected versions. The UAE Cyber Security Council’s October 11, 2024 alert also pointed to GitLab’s October 9 patch release. UAE Cyber Security Council alert
What self-managed administrators should do
The three version numbers above identify the fixes for their branches in the October 2024 release train. They should not be treated as current targets: a release that fixed a 2024 vulnerability may no longer be a supported or appropriate destination. GitLab’s patch guidance recommends upgrading affected installations to the latest patch release for a supported version. GitLab patch release guidance
- Identify the installation. Record its GitLab version, edition (EE or CE), and deployment type (self-managed, GitLab.com, or GitLab Dedicated). The reported arbitrary-branch vulnerability concerned EE; the advisory said GitLab.com and GitLab Dedicated were not affected.
- Check the version against the historical ranges. For a self-managed EE installation, compare its version with the applicable 17.2, 17.3, or 17.4 range above. Do not infer that an installation is safe merely because it is newer than an old threshold; determine whether its branch remains supported and patched.
- Choose a supported destination. Consult GitLab’s live patch and upgrade instructions for the installed version and supported upgrade path. Install the latest patch release for a supported version rather than downgrading or stopping at an old 2024 fix number.
- Complete and verify the upgrade. Follow GitLab’s instructions for the deployment, then confirm the running version and that the upgrade completed successfully. If the system is outside a supported upgrade path or its status is unclear, use GitLab’s current documentation or support channel to establish the correct path before proceeding.
What is established—and what is not
The available 2024 reporting establishes the affected EE release ranges, the reported CVSS 3.1 score, the potential impact, and the stated hosted-service exclusions. It does not establish a CVE identifier, exploitation in the wild, attack telemetry, or the vulnerability’s present-day severity status. The original GitLab release link cited by the report now redirects to a generic release index, so the historical details above are attributed to GitLab as quoted by Hackster.io rather than presented as a currently available vendor advisory.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

