HIGH

CVE-2025-5982

Gitlab GitLab 2025-06-12 CVSS v3.1
CVSS
7.5

Description

An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

Summary dbcve.org

GitLab EE contains an authorization bypass vulnerability where under certain conditions, users can circumvent IP access restrictions (allowlists) configured at the project, group, or instance level to view sensitive information they should not have access to.

Mitigation

Upgrade GitLab EE to version 17.10.8, 17.11.4, or 18.0.2 or later. Until patched, review IP access restriction configurations and consider implementing additional authentication controls such as two-factor authentication.

Weakness (CWE)

CWE-1220

EPSS Score

0.31%
Probability of exploitation in next 30 days
24.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE