MEDIUM
CVE-2025-4976
CVSS
5.3
Description
An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, could have allowed an attacker to access internal notes in GitLab Duo responses.
Summary dbcve.org
This is an information disclosure vulnerability in GitLab EE where improper access controls on internal notes within GitLab Duo responses allow unauthorized access. An attacker could potentially view internal notes that should be restricted.
Mitigation
Upgrade GitLab EE to version 18.0.5 or later, 18.1.3 or later, or 18.2.1 or later to patch this vulnerability.
Weakness (CWE)
CWE-213
EPSS Score
0.42%
Probability of exploitation in next 30 days
36.1th percentile
References
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.