CVE-2025-2045Incorrect Authorization in Gitlab

Severity
4.3MEDIUMNVD
EPSS
0.0%
top 91.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 6
Latest updateApr 16

Description

Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitive project analytics data.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5gitlab/gitlab17.817.8.4+1
NVDgitlab/gitlab17.7.017.7.6+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

1
GHSA
GHSA-2cg5-9vjw-w6vg: Improper authorization in GitLab EE affecting all versions from 172025-03-06

📋Vendor Advisories

3
Red Hat
kernel: ax25: Remove broken autobind2025-04-16
GitLab
CVE-2025-2045: Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with lim2025-03-06
Debian
CVE-2025-2045: gitlab - Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17...2025