Medium severity4.3NVD Advisory· Published Mar 13, 2025· Updated Jun 17, 2026
CVE-2025-0652
CVE-2025-0652
Description
An issue has been discovered in GitLab EE/CE affecting all versions starting from 16.9 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2 could allow unauthorized users to access confidential information intended for internal use only.
Affected products
6cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 16.9
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=16.9.0,<17.7.7
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=16.9.0,<17.7.7
- Range: starting from 16.9 before 17.7.7, starting from 17.8 before 17.8.5, starting from 17.9 before 17.9.2
- Range: starting from 16.9 before 17.7.7, starting from 17.8 before 17.8.5, starting from 17.9 before 17.9.2
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/514532nvdBroken Link
- hackerone.com/reports/2947863nvdPermissions Required
News mentions
1- GitLab Critical Patch Release: 17.9.2, 17.8.5, 17.7.7GitLab Security Releases · Mar 12, 2025