GitLab
cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*, +2 more
- >= 10.6, < 16.9.7
- >= 16.10, < 16.10.5
- >= 16.11, < 16.11.2
A cross-site request forgery (CSRF) vulnerability has been identified in GitLab Community Edition (CE) and Enterprise Edition (EE). This issue affects all versions from 10.6 up to 16.9.7, versions 16.10 prior to 16.10.5, and versions 16.11 prior to 16.11.2. The vulnerability arises in instances configured to use JSON Web Tokens (JWT) as an OmniAuth provider, where CSRF may have been possible.
Exploitation of this vulnerability could lead to cross-site request forgery, allowing an attacker to perform actions on behalf of a user without their consent.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.