CVE-2025-11340Incorrect Authorization in Gitlab

Severity
7.7HIGHNVD
EPSS
0.0%
top 98.56%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 9

Description

GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allowed authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records by exploiting incorrectly scoped GraphQL mutations.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:NExploitability: 3.1 | Impact: 4.0

Affected Packages5 packages

CVEListV5gitlab/gitlab18.318.3.4+1
NVDgitlab/gitlab18.3.018.3.4+1
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-qr9v-c6jg-wx28: GitLab has remediated an issue in GitLab EE affecting all versions from 182025-10-09
OSV
CVE-2025-11340: GitLab has remediated an issue in GitLab EE affecting all versions from 182025-10-09

📋Vendor Advisories

2
GitLab
CVE-2025-11340: GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allo2025-10-09
Debian
CVE-2025-11340: gitlab - GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to ...2025