Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-8647


An issue was discovered in GitLab affecting all versions starting 15.2 to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2. On self hosted installs, it was possible to leak the anti-CSRF-token to an external site while the Harbor integration was enabled.


Published

2024-12-12T12:15:28.297

Last Modified

2025-07-11T19:31:04.157

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.4 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 17.4.6 Yes
Application gitlab gitlab < 17.5.4 Yes
Application gitlab gitlab < 17.6.2 Yes

References