Medium severity4.3NVD Advisory· Published Jul 24, 2025· Updated Jun 17, 2026
CVE-2025-1299
CVE-2025-1299
Description
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions starting from 18.1 before 18.1.3, all versions starting from 18.2 before 18.2.1 that, under circumstances, could have allowed an unauthorized user to read deployment job logs by sending a crafted request.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 15.4
- (no CPE)range: starting from 15.4 before 18.0.5, starting from 18.1 before 18.1.3, starting from 18.2 before 18.2.1
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=15.4,<18.0.5
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=15.4,<18.0.5
- cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:community:*:*:*
- cpe:2.3:a:gitlab:gitlab:18.2:*:*:*:enterprise:*:*:*
- Range: starting from 15.4 before 18.0.5, starting from 18.1 before 18.1.3, starting from 18.2 before 18.2.1
Patches
Vulnerability mechanics
References
2- gitlab.com/gitlab-org/gitlab/-/issues/519696nvdBroken Link
- hackerone.com/reports/2969145nvdPermissions Required
News mentions
1- GitLab Patch Release: 18.2.1, 18.1.3, 18.0.5GitLab Security Releases · Jul 23, 2025