CVE-2024-4597Cross-Site Request Forgery in Gitlab

Severity
6.5MEDIUMNVD
EPSS
0.0%
top 94.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 14

Description

An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5gitlab/gitlab16.716.9.7+2
NVDgitlab/gitlab16.7.016.9.7+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-7xp2-7fx4-46xp: An issue has been discovered in GitLab EE affecting all versions from 162024-05-14

📋Vendor Advisories

2
GitLab
CVE-2024-4597: An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all version2024-05-14
Debian
CVE-2024-4597: gitlab - An issue has been discovered in GitLab EE affecting all versions from 16.7 befor...2024