VYPR
Low severity3.1NVD Advisory· Published Aug 13, 2025· Updated Jun 17, 2026

CVE-2025-2498

CVE-2025-2498

Description

An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • GitLab Inc./GitLabv53 versions
    cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 12.0
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=12.0.0,<18.0.6
    • (no CPE)range: from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2
  • Range: from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2
  • osv-coords
    Range: >= 12.0.0, < 18.0.6

Patches

Vulnerability mechanics

References

2

News mentions

1