CVE-2024-8650: GitLab

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

An issue was discovered in GitLab CE/EE affecting all versions from 15.0 prior to 17.4.6, 17.5 prior to 17.5.4, and 17.6 prior to 17.6.2 that allowed non-member users to view unresolved threads marked as internal notes in public projects merge requests.

Affected products

  • GitLab GitLab: from 15.0.0, before 17.4.6 (fixed in 17.4.6); from 17.5.0, before 17.5.4 (fixed in 17.5.4); from 17.6.0, before 17.6.2 (fixed in 17.6.2)

Published 2024-12-16. Last modified 2026-06-17.