Medium severity5.3NVD Advisory· Published Dec 16, 2024· Updated Jun 17, 2026
CVE-2024-8650
CVE-2024-8650
Description
An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 15.0
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=15.0.0,<17.4.6
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=15.0.0,<17.4.6
- Range: 15.0 to <17.4.6, 17.5 to <17.5.4, 17.6 to <17.6.2
- Range: 15.0 to <17.4.6, 17.5 to <17.5.4, 17.6 to <17.6.2
- osv-coords8 versionspkg:apk/chainguard/gitlab-base-fips-17.6pkg:apk/chainguard/gitlab-cng-fips-17.6pkg:apk/chainguard/gitlab-container-registry-fips-17.6pkg:apk/chainguard/gitlab-elasticsearch-indexer-fips-17.6pkg:apk/chainguard/gitlab-logger-fips-17.6pkg:apk/chainguard/gitlab-shell-fips-17.6pkg:apk/chainguard/gitlab-toolbox-fips-17.6pkg:bitnami/gitlab
< 17.6.5-r0+ 7 more
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: < 17.6.5-r0
- (no CPE)range: >= 15.0.0, < 17.4.6
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/486300nvdExploitIssue TrackingVendor Advisory
- hackerone.com/reports/2705909nvdPermissions Required
News mentions
1- GitLab Patch Release: 17.6.2, 17.5.4, 17.4.6GitLab Security Releases · Dec 11, 2024