PT-2024-4184 · Gitlab · Gitlab Ce/Ee+1

Imreradon

·

Published

2024-05-23

·

Updated

2024-12-16

·

CVE-2023-7045

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions GitLab CE/EE versions 13.11 through 16.10.5 GitLab CE/EE versions 16.11 through 16.11.2 GitLab CE/EE versions 17.0 through 17.0.0
Description A CSRF vulnerability exists within GitLab CE/EE. By leveraging this vulnerability, an attacker could exfiltrate anti-CSRF tokens via the Kubernetes Agent Server (KAS). This could allow a remote attacker to perform a CSRF attack.
Recommendations For GitLab CE/EE versions 13.11 through 16.10.5, update to version 16.10.6 or later. For GitLab CE/EE versions 16.11 through 16.11.2, update to version 16.11.3 or later. For GitLab CE/EE versions 17.0 through 17.0.0, update to version 17.0.1 or later. As a temporary workaround, consider restricting access to the Kubernetes Agent Server (KAS) to minimize the risk of exploitation.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

BDU:2024-04669
BIT-GITLAB-2023-7045
CVE-2023-7045

Affected Products

Gitlab
Gitlab Ce/Ee