VYPR
Unrated severityNVD Advisory· Published Apr 25, 2024· Updated Apr 24, 2026

Incorrect Authorization in GitLab

CVE-2024-4006

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1 where personal access scopes were not honored by GraphQL subscriptions

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

1