An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.
References
Link | Resource |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/438686 |
Configurations
No configuration.
History
No history.
Information
Published : 2024-05-14 15:44
Updated : 2024-05-14 16:11
NVD link : CVE-2024-4597
Mitre link : CVE-2024-4597
CVE.ORG link : CVE-2024-4597
JSON object : View
Products Affected
No product.
CWE
CWE-352
Cross-Site Request Forgery (CSRF)