MEDIUM

CVE-2025-11971

Gitlab GitLab 2025-10-27 CVSS v3.1
CVSS
6.5

Description

GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to trigger unauthorized pipeline executions by manipulating commits.

Summary dbcve.org

GitLab EE versions 10.6 through 18.5.x contained an authorization flaw where an authenticated attacker could manipulate git commits to trigger pipeline executions they should not have access to. This allows unauthorized CI/CD pipeline triggers without proper approval permissions.

Mitigation

Upgrade GitLab EE to versions 18.3.5, 18.4.3, 18.5.1 or later. For GitLab installations, this is a standard patch upgrade requiring backup, staging validation, and production deployment following standard change management.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.23%
Probability of exploitation in next 30 days
14th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE