MEDIUM

CVE-2024-2177

Gitlab GitLab 2024-07-09 CVSS v3.1
CVSS
6.8

Description

A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a crafted payload.

Weakness (CWE)

CWE-1021

EPSS Score

0.65%
Probability of exploitation in next 30 days
49.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE