MEDIUM
CVE-2024-8116
CVSS
5.3
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
0.42%
Probability of exploitation in next 30 days
35.7th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.