CVE-2024-12570: GitLab

Medium severity, CVSS 6.7. EPSS: 0.4% chance of exploitation in the next 30 days.

An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging to the victim.

Affected products

  • GitLab GitLab: from 13.7.0, before 17.4.6 (fixed in 17.4.6); from 17.5.0, before 17.5.4 (fixed in 17.5.4); from 17.6.0, before 17.6.2 (fixed in 17.6.2)

Published 2024-12-12. Last modified 2026-06-17.