MEDIUM

CVE-2025-0362

Gitlab GitLab 2025-04-10 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf.

Summary dbcve.org

This is an authorization vulnerability in GitLab CE/EE where under certain conditions, an attacker could trick users into unintentionally authorizing sensitive actions on their behalf. The specific exploitation mechanism is not detailed in the available description, but it appears to involve social engineering combined with improper authorization handling, likely allowing an attacker to abuse legitimate GitLab workflows or API authorization flows.

Mitigation

Upgrade GitLab to version 17.8.7, 17.9.6, or 17.10.4 or later. Additionally, educate users about not clicking suspicious links and be cautious with authorization requests.

Weakness (CWE)

CWE-1021

EPSS Score

0.3%
Probability of exploitation in next 30 days
22.5th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE