CVE-2024-1211

CVSS 3.1 Score 6.4 of 10 (medium)

Details

Published Jan 31, 2025
CWE ID 352

Summary

CVE-2024-1211 is a vulnerability affecting GitLab CE/EE versions 10.6 to 16.9.7, 16.10 to 16.10.5, and 16.11 to 16.11.2. These versions may allow for cross-site request forgery (CSRF) attacks on GitLab instances that utilize JSON Web Tokens (JWT) as an OmniAuth provider. An attacker could potentially manipulate users into executing malicious actions on the affected GitLab instance through specially crafted links or forms. This vulnerability poses a significant risk to organizations utilizing the affected versions of GitLab and could potentially lead to unauthorized account activity or data breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share