GitLab CE/EE Cross-Site Request Forgery Vulnerability in JWT OmniAuth Integration

Vulnerability

A cross-site request forgery (CSRF) vulnerability has been identified in GitLab Community Edition (CE) and Enterprise Edition (EE). This issue affects all versions from 10.6 up to 16.9.7, versions 16.10 prior to 16.10.5, and versions 16.11 prior to 16.11.2. The vulnerability arises in instances configured to use JSON Web Tokens (JWT) as an OmniAuth provider, where CSRF may have been possible.

Impact

Exploitation of this vulnerability could lead to cross-site request forgery, allowing an attacker to perform actions on behalf of a user without their consent.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
0.6
exploitability
6.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.