CSRF Vulnerability in GitLab CE/EE Affects Multiple Versions
CVE-2024-4994

8.1HIGH

Key Information:

Vendor

Gitlab

Status
Vendor
CVE Published:
20 June 2025

What is CVE-2024-4994?

A Cross-Site Request Forgery (CSRF) vulnerability exists in GitLab CE/EE, affecting versions from 16.1.0 before 16.11.5, 17.0 before 17.0.3, and 17.1 before 17.1.1. This vulnerability allows attackers to exploit GitLab's GraphQL API, potentially executing arbitrary GraphQL mutations without user consent. The flaw can lead to unauthorized actions that compromise the integrity of user data and application functionality.

Affected Version(s)

GitLab 16.1 < 16.11.5

GitLab 17.0.0 < 17.0.3

GitLab 17.1.0 < 17.1.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Thanks [ahacker1](https://hackerone.com/ahacker1) for reporting this vulnerability through our HackerOne bug bounty program
.
CVE-2024-4994 : CSRF Vulnerability in GitLab CE/EE Affects Multiple Versions