Site icon API Security Blog

GitLab 16.9 < 17.4.6 / 17.5 < 17.5.4 / 17.6 < 17.6.2 (CVE-2024-8116)

image
The version of GitLab installed on the remote host is affected by a vulnerability, as follows: An issue has been discovered in GitLab CE/EE affecting all versions from 16.9 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. By using a specific GraphQL query, under specific conditions an unauthorized user can retrieve branch names. (CVE-2024-8116) Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version…Read More

Exit mobile version