CSRF Vulnerability in GitLab CE/EE Affects Multiple Versions
CVE-2024-4994
8.1HIGH
What is CVE-2024-4994?
A Cross-Site Request Forgery (CSRF) vulnerability exists in GitLab CE/EE, affecting versions from 16.1.0 before 16.11.5, 17.0 before 17.0.3, and 17.1 before 17.1.1. This vulnerability allows attackers to exploit GitLab's GraphQL API, potentially executing arbitrary GraphQL mutations without user consent. The flaw can lead to unauthorized actions that compromise the integrity of user data and application functionality.
Affected Version(s)
GitLab 16.1 < 16.11.5
GitLab 17.0.0 < 17.0.3
GitLab 17.1.0 < 17.1.1
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [ahacker1](https://hackerone.com/ahacker1) for reporting this vulnerability through our HackerOne bug bounty program