{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-03T03:58:01.480","vulnerabilities":[{"cve":{"id":"CVE-2024-9773","sourceIdentifier":"cve@gitlab.com","published":"2025-03-27T13:15:35.523","lastModified":"2026-06-17T08:25:13.980","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a maintainer to add malicious code to the CLI commands shown in the UI."},{"lang":"es","value":"Se detectó un problema en GitLab EE que afectaba a todas las versiones (desde la 14.9 hasta la 17.8.6), a todas las versiones (desde la 17.9 hasta la 17.8.3) y a todas las versiones (desde la 17.10 hasta la 17.10.1). Un problema de validación de entrada en la integración del registro Harbor podría haber permitido que un responsable añadiera código malicioso a los comandos CLI mostrados en la interfaz de usuario."}],"affected":[{"source":"cve@gitlab.com","affectedData":[{"vendor":"GitLab","product":"GitLab","defaultStatus":"unaffected","cpes":["cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"],"repo":"git://git@gitlab.com:gitlab-org/gitlab.git","versions":[{"version":"14.9","lessThan":"17.8.6","versionType":"semver","status":"affected"},{"version":"17.9","lessThan":"17.9.3","versionType":"semver","status":"affected"},{"version":"17.10","lessThan":"17.10.1","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@gitlab.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"HIGH","userInteraction":"REQUIRED","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":0.6,"impactScore":2.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H","baseScore":8.0,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.1,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-03-27T13:07:31.748921Z","id":"CVE-2024-9773","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@gitlab.com","type":"Secondary","description":[{"lang":"en","value":"CWE-77"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"14.9.0","versionEndExcluding":"17.8.6","matchCriteriaId":"0087D9FB-3DDA-4DE3-BFAB-D69B51C7F94E"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*","versionStartIncluding":"17.9.0","versionEndExcluding":"17.9.3","matchCriteriaId":"CCB5AC8D-FAC9-4C2B-B273-53D84D1F98B7"},{"vulnerable":true,"criteria":"cpe:2.3:a:gitlab:gitlab:17.10.0:*:*:*:enterprise:*:*:*","matchCriteriaId":"7C528FCC-126C-4DA8-9484-91C9DFAD2585"}]}]}],"references":[{"url":"https://gitlab.com/gitlab-org/gitlab/-/issues/498557","source":"cve@gitlab.com","tags":["Exploit","Issue Tracking"]},{"url":"https://hackerone.com/reports/2671808","source":"cve@gitlab.com","tags":["Permissions Required"]}]}}]}