CVE-2024-8116: Incorrect Authorization in GitLab
An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorised user can retrieve branch names. This is a medium severity issue (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, 5.3). It is now mitigated in the latest release and is assigned CVE-2024-8116.
Other sources
An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.
— MITRE
Affected Software
Remediation
Information
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2024-8116?
CVE-2024-8116 has been classified with a high severity level due to the potential for unauthorized data access.
How do I fix CVE-2024-8116?
To mitigate CVE-2024-8116, update GitLab CE/EE to at least version 17.4.6, 17.5.4, or 17.6.2.
Which versions of GitLab are affected by CVE-2024-8116?
CVE-2024-8116 affects GitLab CE/EE versions from 16.9 to below 17.4.6, from 17.5 to below 17.5.4, and from 17.6 to below 17.6.2.
What type of vulnerability is CVE-2024-8116?
CVE-2024-8116 is an unauthorized access vulnerability allowed through a specific GraphQL query.
Who is impacted by CVE-2024-8116?
Unauthorized users can exploit CVE-2024-8116 to retrieve branch names, impacting the security of GitLab repositories.