HIGH

CVE-2025-2242

Gitlab GitLab 2025-03-27 CVSS v3.1
CVSS
8.8

Description

An improper access control vulnerability in GitLab CE/EE affecting all versions from 17.4 prior to 17.8.6, 17.9 prior to 17.9.3, and 17.10 prior to 17.10.1 allows a user who was an instance admin before but has since been downgraded to a regular user to continue to maintain elevated privileges to groups and projects.

Summary dbcve.org

An improper access control vulnerability in GitLab CE/EE allows users who were previously instance administrators but have since been demoted to regular users to retain elevated privileges over groups and projects they formerly administered. This is a privilege persistence flaw where role-based access controls are not properly enforced upon demotion.

Mitigation

Upgrade to GitLab versions 17.8.6, 17.9.3, or 17.10.1 or later to patch the vulnerability. Additionally, audit all user permissions to identify and revoke any elevated access retained by demoted administrators.

Weakness (CWE)

CWE-863 Incorrect Authorization

EPSS Score

0.35%
Probability of exploitation in next 30 days
29.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE