An issue has been discovered in GitLab CE/EE affecting all previous versions. If the victim is an admin, it was possible to issue a CSRF in System hooks through the API.
2021-04-02T17:15:13.007
2024-11-21T05:49:42.003
Modified
CVSSv3.1: 2.4 (LOW)
AV:N/AC:M/Au:N/C:N/I:P/A:N
8.6
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | gitlab | gitlab | ≤ 13.10.0 | Yes |
| Application | gitlab | gitlab | ≤ 13.10.0 | Yes |