CVE-2024-1211
CVSS 3.1 Score 6.4 of 10 (medium)
Details
Summary
CVE-2024-1211 is a vulnerability affecting GitLab CE/EE versions 10.6 to 16.9.7, 16.10 to 16.10.5, and 16.11 to 16.11.2. These versions may allow for cross-site request forgery (CSRF) attacks on GitLab instances that utilize JSON Web Tokens (JWT) as an OmniAuth provider. An attacker could potentially manipulate users into executing malicious actions on the affected GitLab instance through specially crafted links or forms. This vulnerability poses a significant risk to organizations utilizing the affected versions of GitLab and could potentially lead to unauthorized account activity or data breaches.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- GitLab
Affected Vendors
- GitLab Inc.