CVE-2025-0362
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf.
Summary dbcve.org
This is an authorization vulnerability in GitLab CE/EE where under certain conditions, an attacker could trick users into unintentionally authorizing sensitive actions on their behalf. The specific exploitation mechanism is not detailed in the available description, but it appears to involve social engineering combined with improper authorization handling, likely allowing an attacker to abuse legitimate GitLab workflows or API authorization flows.
Mitigation
Upgrade GitLab to version 17.8.7, 17.9.6, or 17.10.4 or later. Additionally, educate users about not clicking suspicious links and be cautious with authorization requests.