{"id":"CVE-2024-9183","title":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged us…","summary":"GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged us…","severity":"high","cvss":7.7,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N","cwe":["CWE-367"],"vendor":"gitlab","product":"gitlab","affected":["gitlab >= 18.4.0, < 18.4.5","gitlab >= 18.5.0, < 18.5.3","gitlab >= 18.6.0, < 18.6.1"],"patched":["gitlab 18.6.1"],"published":"2025-12-05","updated":"2026-09-26","sourceUpdated":"2026-09-26T21:10:00.130","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2024-9183","references":[{"url":"https://about.gitlab.com/releases/2025/11/26/patch-release-gitlab-18-6-1-released/","label":"cve@gitlab.com"},{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/494478","label":"cve@gitlab.com"},{"url":"https://hackerone.com/reports/2707421","label":"cve@gitlab.com"}],"tags":["nvd"],"epss":0.00246,"epssPercentile":0.14214,"ingestedAt":"2026-09-26T21:38:01.497Z","slug":"CVE-2024-9183","body":"## Overview\n\nGitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged users and perform actions in their context under specific conditions.\n\n## Affected\n\n- `gitlab >= 18.4.0, < 18.4.5`\n- `gitlab >= 18.5.0, < 18.5.3`\n- `gitlab >= 18.6.0, < 18.6.1`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `gitlab 18.6.1`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":42.4,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}