CVE-2025-11971
Description
GitLab has remediated an issue in GitLab EE affecting all versions from 10.6 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to trigger unauthorized pipeline executions by manipulating commits.
Summary dbcve.org
GitLab EE versions 10.6 through 18.5.x contained an authorization flaw where an authenticated attacker could manipulate git commits to trigger pipeline executions they should not have access to. This allows unauthorized CI/CD pipeline triggers without proper approval permissions.
Mitigation
Upgrade GitLab EE to versions 18.3.5, 18.4.3, 18.5.1 or later. For GitLab installations, this is a standard patch upgrade requiring backup, staging validation, and production deployment following standard change management.