Rewterz

Multiple Microsoft Excel Vulnerabilities

April 30, 2025
Rewterz

Hackers Use MS Equation Editor Flaw to Deploy XLoader

April 30, 2025

Multiple GitLab Products Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2024-12619 CVSS:5.2

GitLab could allow a remote authenticated attacker to bypass security restrictions, caused by an improper access control vulnerability.

CVE-2024-8402 CVSS:3.7

An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a Maintainer to introduce malicious code. GitLab allow a local authenticated attacker to execute arbitrary commands on the system, caused by an input validation issue in the Google Cloud IAM integration feature.

Impact

  • Security Bypass
  • Gain Access

Indicators of Compromise

CVE

  • CVE-2024-12619

  • CVE-2024-8402

Affected Vendors

  • GitLab

Affected Products

  • GitLab - 17.9
  • GitLab - 17.8.5
  • GitLab - 17.10

Remediation

Upgrade to the latest version of GitLab, available from the GitLab Website.

CVE-2024-12619

CVE-2024-8402

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.