MEDIUM

CVE-2025-4976

Gitlab GitLab 2025-07-24 CVSS v3.1
CVSS
5.3

Description

An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses.

Summary dbcve.org

This is an information disclosure vulnerability in GitLab EE where improper access controls on internal notes within GitLab Duo responses allow unauthorized access. An attacker could potentially view internal notes that should be restricted.

Mitigation

Upgrade GitLab EE to version 18.0.5 or later, 18.1.3 or later, or 18.2.1 or later to patch this vulnerability.

Weakness (CWE)

CWE-213

EPSS Score

0.42%
Probability of exploitation in next 30 days
36.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE