VDB

CVE-2024-8650

CVE-2024-8650 PUBLISHED

An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.

EPSS 0.17% · 37.5th percentile

Risk Scores

EPSS Score
0.17%
37.5th percentile

Affected Products

VendorProductVersions
Bitnamigitlab15.0.0, 17.6.0, 17.5.0
Bitnamigitlab15.0.0, 17.5.0, 17.6.0

Timeline

  • Jan 21, 1970 Security Advisory
  • Dec 10, 2024 CVE Published
  • Dec 11, 2024 PoC Published
  • Dec 16, 2024 EPSS Score
  • Dec 16, 2024 PoC Published
  • Dec 16, 2024 PoC Published
  • Jan 2, 2025 EPSS Score
  • Jan 18, 2025 EPSS Score
  • Feb 4, 2025 EPSS Score
  • Feb 20, 2025 EPSS Score
  • Mar 9, 2025 EPSS Score
  • Mar 25, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›