HIGH

CVE-2025-1278

Gitlab GitLab 2025-05-09 CVSS v3.1
CVSS
7.5

Description

An issue has been discovered in GitLab CE/EE affecting all versions from 12.0 before 17.9.8, 17.10 before 17.10.6, and 17.11 before 17.11.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

Summary dbcve.org

GitLab CE/EE contains an authentication bypass vulnerability where under certain conditions users can circumvent administrator-configured IP access restrictions, allowing unauthorized access to sensitive information. The vulnerability affects versions 12.0 through 17.9.7, 17.10.0-17.10.5, and 17.11.0-17.11.1.

Mitigation

Upgrade GitLab to version 17.9.8, 17.10.6, or 17.11.2 or later. Review access logs for unauthorized access attempts from IPs outside allowed ranges.

Weakness (CWE)

CWE-1220

EPSS Score

0.34%
Probability of exploitation in next 30 days
27.7th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE