Medium severity6.5NVD Advisory· Published Aug 13, 2025· Updated Jun 17, 2026
CVE-2025-8770
CVE-2025-8770
Description
An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:*:*:*:*range: 18.0
- cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=18.0.0,<18.0.6
- (no CPE)range: >= 18.0 < 18.0.6, >= 18.1 < 18.1.4, >= 18.2 < 18.2.2
Patches
Vulnerability mechanics
References
1- gitlab.com/gitlab-org/gitlab/-/issues/549105nvdBroken Link
News mentions
1- GitLab Patch Release: 18.2.2, 18.1.4, 18.0.6GitLab Security Releases · Aug 13, 2025