CVE-2024-11669: Incorrect Authorization in GitLab

6.5 CVSS

Description

An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could potentially allow unauthorized access to sensitive data due to overly broad application of token scopes.

Classification

CVE ID: CVE-2024-11669

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.5

Affected Products

Vendor: GitLab

Product: GitLab

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.12% (probability of being exploited)

EPSS Percentile: 47.38% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://gitlab.com/gitlab-org/gitlab/-/issues/501528

Timeline