MEDIUM
Incorrect Authorization in GitLab
Published Mar 13, 2025
6.5
MEDIUMCVSS 3.1
EPSS 0.41%
Description
An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only.
Affected products
-
- Version 16.9StatusaffectedConstraints<17.7.7
- Version 17.8StatusaffectedConstraints<17.8.5
- Version 17.9StatusaffectedConstraints<17.9.2
- Version
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to versions 17.7.7, 17.8.5, 17.9.2.
Weaknesses (1)
References (2)
- https://gitlab.com/gitlab-org/gitlab/-/issues/514532 issue-trackingpermissions-requiredBroken Link
- https://hackerone.com/reports/2947863 technical-descriptionexploitpermissions-requiredPermissions Required
| Link | Providers | Tags |
|---|---|---|
| https://gitlab.com/gitlab-org/gitlab/-/issues/514532 | issue-trackingpermissions-requiredBroken Link | |
| https://hackerone.com/reports/2947863 | technical-descriptionexploitpermissions-requiredPermissions Required |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitLab
Published Mar 13, 2025
Updated Mar 14, 2025
Reserved Jan 22, 2025
Link CVE-2025-0652
CISA Vulnrichment
Updated Mar 14, 2025