MEDIUM

CVE-2024-4597

Gitlab GitLab 2024-05-14 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.

Summary dbcve.org

A CSRF vulnerability in GitLab EE allows attackers to force users with active SAML sessions to approve merge requests without consent. The MR approval endpoint lacks proper CSRF token validation, enabling malicious forged requests when a victim visits an attacker-controlled page while authenticated.

Mitigation

Upgrade to GitLab versions 16.9.7, 16.10.5, 16.11.2 or later. Ensure CSRF protection is enabled and functional for all state-changing operations, particularly merge request approvals.

Weakness (CWE)

CWE-352 Cross-Site Request Forgery (CSRF)

EPSS Score

0.28%
Probability of exploitation in next 30 days
21th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE