CVE-2025-1540Incorrect Authorization in Gitlab

Severity
4.2MEDIUMNVD
EPSS
0.1%
top 76.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 6
Latest updateJul 10

Description

An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to 17.7.4, and 17.8 prior to 17.8.2. It was possible for a user added as an External to read and clone internal projects under certain circumstances."

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:NExploitability: 1.6 | Impact: 2.5

Affected Packages5 packages

CVEListV5gitlab/gitlab17.517.6.5+2
NVDgitlab/gitlab17.5.017.6.5+2
debiandebian/gitlab< gitlab 17.6.5-1 (sid)
gitlabgitlab/gitlab

🔴Vulnerability Details

2
GHSA
GHSA-6xr7-mv6q-jx4q: An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 172025-03-06
OSV
CVE-2025-1540: An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 172025-03-06

📋Vendor Advisories

3
Red Hat
kernel: Linux kernel (PTP): Denial of Service due to recursive locking in virtual clock handling2025-07-10
GitLab
CVE-2025-1540: An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated instances affecting all versions from 17.5 prior to 17.6.5, 17.7 prior to2025-03-06
Debian
CVE-2025-1540: gitlab - An issue has been discovered in GitLab CE/EE for Self-Managed and Dedicated inst...2025