Unrated severityNVD Advisory· Published Apr 25, 2024· Updated Apr 24, 2026
Incorrect Authorization in GitLab
CVE-2024-4006
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1 where personal access scopes were not honored by GraphQL subscriptions
Affected products
3- Range: >=16.7 <16.9.6, >=16.10 <16.10.4, >=16.11 <16.11.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- gitlab.com/gitlab-org/gitlab/-/issues/455805mitreissue-trackingpermissions-required
News mentions
1- GitLab Patch Release: 16.11.1, 16.10.4, 16.9.6GitLab Security Releases · Apr 24, 2024