CVE-2024-2177: GitLab

Medium severity, CVSS 6.8. EPSS: 0.7% chance of exploitation in the next 30 days.

A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a crafted payload.

Affected products

  • GitLab GitLab: from 16.3.0, before 16.11.5 (fixed in 16.11.5); from 17.0.0, before 17.0.3 (fixed in 17.0.3); version 17.1.0 only

Published 2024-07-09. Last modified 2026-06-17.