Medium severity6.4NVD Advisory· Published Apr 10, 2025· Updated Jun 17, 2026
CVE-2025-0362
CVE-2025-0362
Description
An issue has been discovered in GitLab CE/EE affecting all versions from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4. Under certain conditions, an attacker could potentially trick users into unintentionally authorizing sensitive actions on their behalf.
Affected products
6cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 7.7
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=7.7.0,<17.8.7
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=7.7.0,<17.8.7
- (no CPE)range: from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4
- Range: from 7.7 before 17.8.7, 17.9 before 17.9.6, and 17.10 before 17.10.4
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/512425nvdBroken Link
- hackerone.com/reports/2926425nvdPermissions Required
News mentions
1- GitLab Patch Release: 17.10.4, 17.9.6, 17.8.7GitLab Security Releases · Apr 9, 2025