VDB

CVE-2024-2177

CVE-2024-2177 PUBLISHED

A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a crafted payload.

EPSS 0.11% · 28.7th percentile

Risk Scores

EPSS Score
0.11%
28.7th percentile

Affected Products

VendorProductVersions
Bitnamigitlab16.3.0, 17.0.0, 17.1.0
Bitnamigitlab16.3.0, 17.0.0, 17.1.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Jun 26, 2024 CVE Published
  • Jul 9, 2024 PoC Published
  • Jul 10, 2024 EPSS Score
  • Aug 1, 2024 EPSS Score
  • Aug 27, 2024 EPSS Score
  • Sep 18, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 9, 2024 EPSS Score
  • Oct 31, 2024 EPSS Score
  • Nov 22, 2024 EPSS Score
  • Dec 15, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›