An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a Maintainer to introduce malicious code.
CVE ID: CVE-2024-8402
CVSS Base Severity: LOW
CVSS Base Score: 3.7
CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:C/C:L/I:L/A:N
Vendor: GitLab
Product: GitLab
EPSS Score: 0.02% (probability of being exploited)
EPSS Percentile: 2.57% (scored less or equal to compared to others)
EPSS Date: 2025-04-11 (when was this score calculated)