MEDIUM

CVE-2025-0652

Gitlab GitLab 2025-03-13 CVSS v3.1
CVSS
6.5

Description

An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only.

Summary dbcve.org

This is an access control vulnerability in GitLab EE/CE where unauthorized users can access confidential information intended for internal use only. The issue affects multiple version branches (16.9.x, 17.8.x, 17.9.x) before the patched releases.

Mitigation

Upgrade GitLab to version 17.7.7, 17.8.5, 17.9.2 or later. If immediate patching is not possible, review and restrict access controls for internal-only resources as a temporary measure.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.41%
Probability of exploitation in next 30 days
35th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE