GitLab CE/EE Pipeline Trigger Vulnerability for Maintainers

Vulnerability

A vulnerability exists in GitLab Community Edition (CE) and Enterprise Edition (EE) versions 17.1 prior to 17.6.0. This issue allows an attacker with a maintainer role to initiate a pipeline as the project owner under specific conditions.

Impact

Exploitation of this vulnerability could lead to unauthorized pipeline triggers, potentially allowing for malicious actions to be executed within the context of the project owner.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
0.6
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.