An issue was discovered in GitLab CE/EE affecting all versions starting from 16.1 prior to 17.4.6, starting from 17.5 prior to 17.5.4, and starting from 17.6 prior to 17.6.2, injection of NEL headers in k8s proxy response could lead to session data exfiltration.
                
            References
                    | Link | Resource | 
|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/504707 | Exploit Issue Tracking Vendor Advisory | 
| https://hackerone.com/reports/2813673 | Permissions Required | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    11 Jul 2025, 20:33
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:* cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:* | |
| References | () https://gitlab.com/gitlab-org/gitlab/-/issues/504707 - Exploit, Issue Tracking, Vendor Advisory | |
| References | () https://hackerone.com/reports/2813673 - Permissions Required | |
| First Time | Gitlab Gitlab gitlab | |
| Summary | 
 | 
12 Dec 2024, 12:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2024-12-12 12:15
Updated : 2025-07-11 20:33
NVD link : CVE-2024-11274
Mitre link : CVE-2024-11274
CVE.ORG link : CVE-2024-11274
JSON object : View
Products Affected
                gitlab
- gitlab
CWE
                
                    
                        
                        CWE-601
                        
            URL Redirection to Untrusted Site ('Open Redirect')
