CVE-2024-11669: Incorrect Authorization in GitLab
An issue was discovered in GitLab CE/EE affecting all versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. Certain API endpoints could potentially allow unauthorized access to sensitive data due to overly broad application of token scopes.
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-11669?
CVE-2024-11669 is classified as a high severity vulnerability due to its potential for unauthorized access to sensitive data.
How do I fix CVE-2024-11669?
To fix CVE-2024-11669, update your GitLab installation to version 17.4.5 or later for versions 16.9.8 through 17.4.5, 17.5.3 or later for versions 17.5.0 through 17.5.3, and 17.6.1 or later for version 17.6.0.
Which versions are affected by CVE-2024-11669?
CVE-2024-11669 affects GitLab CE/EE versions from 16.9.8 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1.
What type of vulnerability is CVE-2024-11669?
CVE-2024-11669 is an authorization issue that may lead to unauthorized access to sensitive data.
Who is impacted by CVE-2024-11669?
Users of GitLab CE/EE in the specified affected versions are impacted by CVE-2024-11669.