An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/438686 | Broken Link |
https://gitlab.com/gitlab-org/gitlab/-/issues/438686 | Broken Link |
Configurations
Configuration 1 (hide)
|
History
13 Dec 2024, 16:55
Type | Values Removed | Values Added |
---|---|---|
First Time |
Gitlab
Gitlab gitlab |
|
CPE | cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* |
|
References | () https://gitlab.com/gitlab-org/gitlab/-/issues/438686 - Broken Link |
21 Nov 2024, 09:43
Type | Values Removed | Values Added |
---|---|---|
References | () https://gitlab.com/gitlab-org/gitlab/-/issues/438686 - | |
Summary |
|
14 May 2024, 15:44
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-05-14 15:44
Updated : 2024-12-13 16:55
NVD link : CVE-2024-4597
Mitre link : CVE-2024-4597
CVE.ORG link : CVE-2024-4597
JSON object : View
Products Affected
gitlab
- gitlab
CWE
CWE-352
Cross-Site Request Forgery (CSRF)