MEDIUM

CVE-2024-1539

Gitlab GitLab 2025-02-05 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab EE affecting all versions starting from 15.2 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose updates to issues to a banned group member using the API.

Summary dbcve.org

GitLab EE versions prior to 16.9.7, 16.10.5, and 16.11.2 contain an information disclosure vulnerability where the API incorrectly allowed banned group members to receive updates about issues they should no longer have access to. This is an authorization bypass in the issue update notification API.

Mitigation

Upgrade GitLab EE to version 16.9.7, 16.10.5, 16.11.2 or later. Alternatively, ensure no banned users remain in groups with access to sensitive issues.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

0.35%
Probability of exploitation in next 30 days
28.4th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE