CVE-2025-2615Sensitive Info Insertion into Sent Data in Gitlab

Severity
6.5MEDIUMNVD
EPSS
0.0%
top 98.42%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 15

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could have allowed a blocked user to access sensitive information by establishing GraphQL subscriptions through WebSocket connections.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages5 packages

CVEListV5gitlab/gitlab16.718.3.6+2
NVDgitlab/gitlab16.7.018.3.6+2
debiandebian/gitlab
gitlabgitlab/gitlab

🔴Vulnerability Details

2
OSV
CVE-2025-2615: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 162025-11-15
GHSA
GHSA-rm4r-vwvw-vj67: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 162025-11-15

📋Vendor Advisories

3
GitLab
CVE-2025-2615: GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2, that could2025-11-15
Debian
CVE-2025-2615: gitlab - GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.7 ...2025
Citrix
Citrix Security Bulletin CTX220771