Unrated severityNVD Advisory· Published May 9, 2024· Updated Aug 29, 2024
Cross-Site Request Forgery (CSRF) in GitLab
CVE-2024-4597
Description
An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.
Affected products
3- Range: >=16.7, <16.9.7 || >=16.10, <16.10.5 || >=16.11, <16.11.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- gitlab.com/gitlab-org/gitlab/-/issues/438686mitreissue-trackingpermissions-required
News mentions
1- GitLab Patch Release: 16.11.2, 16.10.5, 16.9.7GitLab Security Releases · May 8, 2024