A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://gitlab.com/gitlab-org/gitlab/-/issues/324397 | broken link |
https://hackerone.com/reports/1122408 | permissions required |
https://gitlab.com/gitlab-org/cves/-/blob/master/2021/CVE-2021-22224.json | third party advisory |