CVE-2025-5195 PUBLISHED

Authorization Bypass Through User-Controlled Key in GitLab

Assigner: GitLab
Reserved: 26.05.2025 Published: 12.06.2025 Updated: 12.06.2025

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. It was possible for authenticated users to access arbitrary compliance frameworks, leading to unauthorized data disclosure.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor GitLab
Product GitLab
Versions Default: unaffected
  • affected from 17.9 to 17.10.8 (excl.)
  • affected from 17.11 to 17.11.4 (excl.)
  • affected from 18.0 to 18.0.2 (excl.)

Solutions

Upgrade to versions 17.10.8, 17.11.4, 18.0.2 or above.

Credits

  • This vulnerability has been discovered internally by GitLab team. finder

References

Problem Types

  • CWE-639: Authorization Bypass Through User-Controlled Key CWE