CVE-2024-4597
Last modified
CVE-2024-4597 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
An issue has been discovered in GitLab EE affecting all versions from 16.7 before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. An attacker could force a user with an active SAML session to approve an MR via CSRF.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gitlab | Gitlab | >= 16.7.0, < 16.9.7 |
| Gitlab | Gitlab | >= 16.10.0, < 16.10.5 |
| Gitlab | Gitlab | >= 16.11.0, < 16.11.2 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-4597?
How severe is CVE-2024-4597?
How do I fix CVE-2024-4597?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-45960Zenario 9.7.61188 allows authenticated admin users to upload…4.8
- CVE-2024-45962October 3.6.30 allows an authenticated admin account to uplo…4.7
- CVE-2024-45964Zenario 9.7.61188 is vulnerable to Cross Site Scripting (XSS…4.8
- CVE-2024-45965Contao before 5.5.6 allows XSS via an SVG document. This aff…5.4
- CVE-2024-45967Pagekit 1.0.18 is vulnerable to Cross Site Scripting (XSS) i…4.7
- CVE-2024-45969NULL pointer dereference in the MMS Client in MZ Automation …7.5
- CVE-2024-45970Multiple Buffer overflows in the MMS Client in MZ Automation…9.8
- CVE-2024-45971Multiple Buffer overflows in the MMS Client in MZ Automation…9.8
- CVE-2024-45979A host header injection vulnerability in Lines Police CAD 1.…8.8
- CVE-2024-4598An information disclosure vulnerability exists in multiple W…6.5
- CVE-2024-45980A host header injection vulnerability in MEANStore 1.0 allow…8.8
- CVE-2024-45981A host header injection vulnerability in BookReviewLibrary 1…8.8
Are you affected by CVE-2024-4597?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
