CVE-2025-0516

MEDIUM

GitLab CE/EE <17.7.4-17.8.2 - Privilege Escalation

Title source: llm

Description

Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow users with limited permissions to perform unauthorized actions on critical project data.

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 10.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Classification

CWE
CWE-863
Status published

Affected Products (2)

gitlab/gitlab < 17.7.4
gitlab/gitlab < 17.7.4

Timeline

Published Feb 12, 2025
Tracked Since Feb 18, 2026