MEDIUM
CVE-2024-8650
CVSS
5.3
Description
An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
0.49%
Probability of exploitation in next 30 days
41th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.