---
id: CVE-2024-9183
title: >-
  GitLab has remediated an issue in GitLab CE/EE affecting all versions from
  18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that
  could have allowed an authenticated user to obtain credentials from
  higher-privileged us…
summary: >-
  GitLab has remediated an issue in GitLab CE/EE affecting all versions from
  18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that
  could have allowed an authenticated user to obtain credentials from
  higher-privileged us…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:N'
cwe:
  - CWE-367
vendor: gitlab
product: gitlab
affected:
  - 'gitlab >= 18.4.0, < 18.4.5'
  - 'gitlab >= 18.5.0, < 18.5.3'
  - 'gitlab >= 18.6.0, < 18.6.1'
patched:
  - gitlab 18.6.1
published: '2025-12-05'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T21:10:00.130'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-9183'
references:
  - url: >-
      https://about.gitlab.com/releases/2025/11/26/patch-release-gitlab-18-6-1-released/
    label: cve@gitlab.com
  - url: 'https://gitlab.com/gitlab-org/gitlab/-/issues/494478'
    label: cve@gitlab.com
  - url: 'https://hackerone.com/reports/2707421'
    label: cve@gitlab.com
tags:
  - nvd
epss: 0.00246
epssPercentile: 0.14214
ingestedAt: '2026-09-26T21:38:01.497Z'
---

## Overview

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged users and perform actions in their context under specific conditions.

## Affected

- `gitlab >= 18.4.0, < 18.4.5`
- `gitlab >= 18.5.0, < 18.5.3`
- `gitlab >= 18.6.0, < 18.6.1`

## Remediation

Upgrade past the affected range:

- `gitlab 18.6.1`
