s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-2024-4994

📛 CVE Title

Cross-Site Request Forgery (CSRF) in GitLab

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on GitLab's GraphQL API leading to the execution of arbitrary GraphQL mutations.

Overview

State
PUBLISHED
Assigner (CNA)
GitLab
CVSS severity
HIGH
CVSS score
CVSS 8.1 / 10 8.1 8.1 / 10
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Effective score
8.1 / 10 HIGH source: CNA overview
CWE(s)
CWE-352
Reserved
2024-05-16
Published
2025-06-20 20:14 UTC
Last updated
2025-06-23 17:22 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/4xxx/CVE-2024-4994.json
Linked Threat
CVE-2024-4994 — Cross-Site Request Forgery (CSRF) in GitLab

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2024-54992
Assigner
GitLab
Published
Jun 20, 2025, 6:14:37 PM
Updated
Jun 23, 2025, 3:22:37 PM
EUVD base score (CVSS 3.1)
8.1 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
EUVD-reported EPSS
0.0900
Vendors
GitLab
Products
GitLab (16.1 <16.11.5)
GitLab (17.1.0 <17.1.1)
GitLab (17.0.0 <17.0.3)
Aliases
GHSA-44j4-r7x2-mjhj

ENISA description: An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on GitLab's GraphQL API leading to the execution of arbitrary GraphQL mutations.

EUVD references (2)

Affected products (1)

VendorProductVersionsPlatforms
GitLab GitLab 16.1 (affected), 17.0.0 (affected), 17.1.0 (affected)

Vendor references (2)

References embedded in the original CVE record by the assigning CNA.

Web references (6)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

Remediations (17)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:dailysecurityreview.com

    Redis Releases Update to Fix CVE -2025-49844 Critical RCE Vulnerability A critical use-after-free vulnerability in Redis ( CVE -2025-49844) enables remote code execution via Lua scripting. Affecting all versions up to 8.2.1, the flaw is already being exploited in the wild, prompting urgent patching and mitigation calls from major security vendors.

    2026-08-05 15:27 UTC
  • web:msrc.microsoft.com

    Security Update Guide - Microsoft Security Response Center

    2026-08-05 15:27 UTC
  • web:nvd.nist.gov

    Description In the Linux kernel, the following vulnerability has been resolved: parisc: fix a possible DMA corruption ARCH_DMA_MINALIGN was defined as 16 - this is too small - it may be possible that two unrelated 16-byte allocations share a cache line. If one of these allocations is written using DMA and the other is written using cached write, the value that was written with DMA may be ...

    2026-08-05 15:27 UTC
  • web:www.microsoft.com

    Help protect your computing environment by keeping up to date on Microsoft technical security notifications. Security Update Guide Notifications Microsoft's free Security Update Guide Notifications provide links to security-related software updates and notification of re-released security updates. These notifications are sent via email throughout the month as needed. You can choose the type of ...

    2026-08-05 15:27 UTC
  • web:www.nist.gov

    NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation's cybersecurity infrastructure.

    2026-08-05 15:27 UTC
  • web:www.cisa.gov

    The median time for full resolution rose to 43 days. Defenders need greater clarity and speed to patch systems in today's threat landscape. We must flip the script on patching prioritization: patch smarter, not harder.

    2026-08-05 15:27 UTC
  • web:cybersecuritynews.com

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued Binding Operational Directive (BOD) 26-04, titled "Prioritizing Security Updates Based on Risk," compelling all Federal Civilian Executive Branch (FCEB) agencies to remediate the most dangerous known exploited vulnerabilities within just three calendar days.

    2026-08-05 15:27 UTC
  • web:www.esri.com

    Key highlights The ArcGIS Server Security 2025 update 2 is available This patch resolves 10 Medium severity vulnerabilities This security patch is cumulative, and includes fixes provided in the ArcGIS Server Security 2025 update 1.

    2026-05-22 10:39 UTC
  • web:www.ibm.com

    IBM MQ provides periodic maintenance releases ( Fix Packs), and Cumulative Security Updates, for Version 9.4.0 Long Term Support (LTS). The following is a complete listing of available fixes grouped by maintenance delivery.

    2026-05-22 10:39 UTC
  • web:www.secure.com

    Learn the difference between vulnerability remediation and mitigation , and how a risk-based strategy can strengthen your security posture.

    2026-05-22 10:39 UTC
  • web:www.virustotal.com

    Streamline your investigations with Google Threat Intelligence Agentic and the new Dark Web (DDW) module. Perform hunting and pivoting across forums using natural language or specific modifiers. Bridge threat actor identities and map global operations easy.

    2026-05-22 10:39 UTC
  • web:github.com

    NOTE: NVMeFix supports up to macOS 26, some features might not be available on newer versions as of now, like the timeout panic fix . NVMeFix is a set of patches for the Apple NVMe storage driver, IONVMeFamily. Its goal is to improve compatibility with non-Apple SSDs. It may be used both on Apple and non-Apple computers. The following features are implemented: Autonomous Power State Transition ...

    2026-05-22 10:39 UTC
  • web:krebsonsecurity.com

    Microsoft Corp. today issued security updates to fix more than 80 vulnerabilities in its Windows operating systems and software. There are no known "zero-day" or actively exploited ...

    2026-05-22 10:39 UTC
  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

    2026-05-22 10:39 UTC
  • web:redis.io

    What is the vulnerability? [ CVE -2025-49844] Lua use-after-free may lead to remote code execution. CVSS Score: 10.0 (Critical) An authenticated user may use a specially crafted Lua script to manipulate the garbage collector, trigger a use-after-free and potentially lead to remote code execution.

    2026-05-22 10:39 UTC
  • web:www.bugcrowd.com

    Vulnerability mitigation is typically considered a temporary or interim solution. While mitigation measures can reduce the immediate risk associated with vulnerabilities, they may not provide a permanent fix . Organizations should aim to prioritize and plan for complete vulnerability remediation whenever feasible and allocate resources accordingly.

    2026-05-22 10:39 UTC
  • web:www.cve.org

    At cve .org, we provide the authoritative reference method for publicly known information-security vulnerabilities and exposures

    2026-05-22 10:39 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2024-4994.json.

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2024-4994",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2025-06-23T15:22:30.992339Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2025-06-23T15:22:37.297Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "cpes": [
            "cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*"
          ],
          "defaultStatus": "unaffected",
          "product": "GitLab",
          "repo": "git://git@gitlab.com:gitlab-org/gitlab.git",
          "vendor": "GitLab",
          "versions": [
            {
              "lessThan": "16.11.5",
              "status": "affected",
              "version": "16.1",
              "versionType": "semver"
            },
            {
              "lessThan": "17.0.3",
              "status": "affected",
              "version": "17.0.0",
              "versionType": "semver"
            },
            {
              "lessThan": "17.1.1",
              "status": "affected",
              "version": "17.1.0",
              "versionType": "semver"
            }
          ]
        }
      ],
      "credits": [
        {
          "lang": "en",
          "type": "finder",
          "value": "Thanks [ahacker1](https://hackerone.com/ahacker1) for reporting this vulnerability through our HackerOne bug bounty program"
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 before 17.1.1 which allowed for a CSRF attack on GitLab's GraphQL API leading to the execution of arbitrary GraphQL mutations."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "attackComplexity": "LOW",
            "attackVector": "NETWORK",
            "availabilityImpact": "NONE",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "REQUIRED",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N",
            "version": "3.1"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-352",
              "description": "CWE-352: Cross-Site Request Forgery (CSRF)",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2025-06-20T18:14:37.887Z",
        "orgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a",
        "shortName": "GitLab"
      },
      "references": [
        {
          "name": "GitLab Issue #462012",
          "tags": [
            "issue-tracking",
            "permissions-required"
          ],
          "url": "https://gitlab.com/gitlab-org/gitlab/-/issues/462012"
        },
        {
          "name": "HackerOne Bug Bounty Report #2473644",
          "tags": [
            "technical-description",
            "exploit",
            "permissions-required"
          ],
          "url": "https://hackerone.com/reports/2473644"
        }
      ],
      "solutions": [
        {
          "lang": "en",
          "value": "Upgrade to versions 16.11.5, 17.0.3, 17.1.1 or above."
        }
      ],
      "title": "Cross-Site Request Forgery (CSRF) in GitLab"
    }
  },
  "cveMetadata": {
    "assignerOrgId": "ceab7361-8a18-47b1-92ba-4d7d25f6715a",
    "assignerShortName": "GitLab",
    "cveId": "CVE-2024-4994",
    "datePublished": "2025-06-20T18:14:37.887Z",
    "dateReserved": "2024-05-16T10:30:52.440Z",
    "dateUpdated": "2025-06-23T15:22:37.297Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1"
}