MEDIUM
CVE-2025-2246
CVSS
5.3
Description
An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.
Summary dbcve.org
A vulnerability in GitLab CE/EE allows unauthenticated users to query the GraphQL API and access sensitive manual CI/CD variables. This occurs due to insufficient authorization checks on GraphQL endpoints, enabling information disclosure of variables that may contain secrets, tokens, or other credentials.
Mitigation
Upgrade GitLab to version 18.1.5, 18.2.5, or 18.3.1 (or later) to remediate the unauthorized access to CI/CD variables.
Weakness (CWE)
CWE-862
Missing Authorization
EPSS Score
0.28%
Probability of exploitation in next 30 days
20.3th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.