MEDIUM
CVE-2025-0652
CVSS
6.5
Description
An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only.
Summary dbcve.org
This is an access control vulnerability in GitLab EE/CE where unauthorized users can access confidential information intended for internal use only. The issue affects multiple version branches (16.9.x, 17.8.x, 17.9.x) before the patched releases.
Mitigation
Upgrade GitLab to version 17.7.7, 17.8.5, 17.9.2 or later. If immediate patching is not possible, review and restrict access controls for internal-only resources as a temporary measure.
Weakness (CWE)
CWE-863
Incorrect Authorization
EPSS Score
0.41%
Probability of exploitation in next 30 days
35th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.