CVE Vulnerabilities

CVE-2024-9183

Time-of-check Time-of-use (TOCTOU) Race Condition

Published: Dec 05, 2025 | Modified: Dec 10, 2025
CVSS 3.x
6.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged users and perform actions in their context under specific conditions.

Weakness

The product checks the state of a resource before using that resource, but the resource’s state can change between the check and the use in a way that invalidates the results of the check.

Affected Software

Name Vendor Start Version End Version
Gitlab Gitlab 18.4.0 (including) 18.4.5 (excluding)
Gitlab Gitlab 18.5.0 (including) 18.5.3 (excluding)
Gitlab Gitlab 18.6.0 (including) 18.6.1 (excluding)

Potential Mitigations

References