CVE-2025-2242
Description
An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.
Summary dbcve.org
An improper access control vulnerability in GitLab CE/EE allows users who were previously instance administrators but have since been demoted to regular users to retain elevated privileges over groups and projects they formerly administered. This is a privilege persistence flaw where role-based access controls are not properly enforced upon demotion.
Mitigation
Upgrade to GitLab versions 17.8.6, 17.9.3, or 17.10.1 or later to patch the vulnerability. Additionally, audit all user permissions to identify and revoke any elevated access retained by demoted administrators.