MEDIUM
CVE-2024-9387
CVSS
6.4
Description
An issue was discovered in GitLab CE/EE affecting all versions from 11.8 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could potentially perform an open redirect against a given releases API endpoint.
Weakness (CWE)
CWE-601
Open Redirect
EPSS Score
0.39%
Probability of exploitation in next 30 days
32.5th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.