6.8

CVE-2024-2177

Exploit

Improper Restriction of Rendered UI Layers or Frames in GitLab

A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a crafted payload.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Gitlab ≫ GitLab SwEdition community Version >= 16.3.0 < 16.11.5
Gitlab ≫ GitLab SwEdition enterprise Version >= 16.3.0 < 16.11.5
Gitlab ≫ GitLab SwEdition community Version >= 17.0.0 < 17.0.3
Gitlab ≫ GitLab SwEdition enterprise Version >= 17.0.0 < 17.0.3
Gitlab ≫ GitLab Version 17.1.0 SwEdition community
Gitlab ≫ GitLab Version 17.1.0 SwEdition enterprise
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.65% 0.463
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 6.8 1.6 5.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
cve@gitlab.com 6.8 1.6 5.2
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N
CWE-1021 Improper Restriction of Rendered UI Layers or Frames

The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.

https://gitlab.com/gitlab-org/gitlab/-/issues/444467
Exploit
Issue Tracking
https://hackerone.com/reports/2383443
Permissions Required