An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could potentially allow unauthorized access to sensitive data due to overly broad application of token scopes.
CVE ID: CVE-2024-11669
CVSS Base Severity: MEDIUM
CVSS Base Score: 6.5
Vendor: GitLab
Product: GitLab
EPSS Score: 0.12% (probability of being exploited)
EPSS Percentile: 47.38% (scored less or equal to compared to others)
EPSS Date: 2025-02-03 (when was this score calculated)