Description
A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging this vulnerability, an attacker could exfiltrate anti-CSRF tokens via the Kubernetes Agent Server (KAS).
No analysis available yet.
Remediation
Vendor Solution
Upgrade to versions 16.10.6, 16.11.3, 17.0.1 or above.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-59232 | A CSRF vulnerability exists within GitLab CE/EE from versions 13.11 before 16.10.6, from 16.11 before 16.11.3, from 17.0 before 17.0.1. By leveraging this vulnerability, an attacker could exfiltrate anti-CSRF tokens via the Kubernetes Agent Server (KAS). |
References
History
Mon, 16 Dec 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:17.0.0:*:*:*:enterprise:*:*:* |
Wed, 18 Sep 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 29 Aug 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Gitlab
Gitlab gitlab |
|
| CPEs | cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Gitlab
Gitlab gitlab |
Status: PUBLISHED
Assigner: GitLab
Published:
Updated: 2024-09-18T13:11:01.842Z
Reserved: 2023-12-21T13:30:38.389Z
Link: CVE-2023-7045
Updated: 2024-08-02T08:50:07.755Z
Status : Analyzed
Published: 2024-05-23T11:15:23.153
Modified: 2024-12-16T14:53:47.797
Link: CVE-2023-7045
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD