MEDIUM
CVE-2024-1539
CVSS
5.3
Description
An issue has been discovered in GitLab EE affecting all versions starting from 15.2 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. It was possible to disclose updates to issues to a banned group member using the API.
Summary dbcve.org
GitLab EE versions prior to 16.9.7, 16.10.5, and 16.11.2 contain an information disclosure vulnerability where the API incorrectly allowed banned group members to receive updates about issues they should no longer have access to. This is an authorization bypass in the issue update notification API.
Mitigation
Upgrade GitLab EE to version 16.9.7, 16.10.5, 16.11.2 or later. Alternatively, ensure no banned users remain in groups with access to sensitive issues.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
0.35%
Probability of exploitation in next 30 days
28.4th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.