VDB

CVE-2024-8116

CVE-2024-8116 PUBLISHED

An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names.

EPSS 0.16% · 35.9th percentile

Risk Scores

EPSS Score
0.16%
35.9th percentile

Affected Products

VendorProductVersions
Bitnamigitlab16.9.0, 17.5.0, 17.6.0
Bitnamigitlab16.9.0, 17.6.0, 17.5.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Dec 10, 2024 CVE Published
  • Dec 11, 2024 PoC Published
  • Dec 16, 2024 EPSS Score
  • Dec 16, 2024 PoC Published
  • Dec 16, 2024 PoC Published
  • Jan 2, 2025 EPSS Score
  • Jan 18, 2025 EPSS Score
  • Feb 4, 2025 EPSS Score
  • Feb 20, 2025 EPSS Score
  • Mar 9, 2025 EPSS Score
  • Mar 25, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›