Home

Description

An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 before 16.9.6, all versions starting from 16.10 before 16.10.4, all versions starting from 16.11 before 16.11.1 where personal access scopes were not honored by GraphQL subscriptions

PUBLISHED Reserved 2024-04-19 | Published 2024-04-25 | Updated 2026-04-24 | Assigner GitLab




MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Problem types

CWE-863: Incorrect Authorization

Product status

Default status
unaffected

16.7 (semver) before 16.9.6
affected

16.10 (semver) before 16.10.4
affected

16.11 (semver) before 16.11.1
affected

Credits

This vulnerability was internally discovered and reported by a GitLab team member, [Dylan Griffith](https://gitlab.com/DylanGriffith) finder

References

gitlab.com/gitlab-org/gitlab/-/issues/455805 (GitLab Issue #455805) issue-tracking

gitlab.com/gitlab-org/gitlab/-/issues/455805 (GitLab Issue #455805) issue-tracking permissions-required

cve.org (CVE-2024-4006)

nvd.nist.gov (CVE-2024-4006)

Download JSON