CVE-2024-11669Incorrect Authorization in Gitlab

Severity
7.5HIGHNVD
EPSS
0.0%
top 95.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 26

Description

An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could potentially allow unauthorized access to sensitive data due to overly broad application of token scopes.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

CVEListV5gitlab/gitlab17.517.5.3+1
NVDgitlab/gitlab16.9.817.4.5+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2024-11669: An issue was discovered in GitLab CE/EE affecting all versions from 162024-11-26
GHSA
GHSA-v84c-53c6-xmmp: An issue was discovered in GitLab CE/EE affecting all versions from 162024-11-26

📋Vendor Advisories

2
GitLab
CVE-2024-11669: An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endp2024-11-26
Debian
CVE-2024-11669: gitlab - An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 befor...2024