CVE-2025-0516

EUVD-2025-1730
Improper Authorization in GitLab CE/EE affecting all versions from 17.7 prior to 17.7.4, 17.8 prior to 17.8.2 allow users with limited permissions to perform unauthorized actions on critical project data.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
gitlabgitlab
17.7.0 ≤
𝑥
< 17.7.4
gitlabgitlab
17.7.0 ≤
𝑥
< 17.7.4
gitlabgitlab
17.8.0 ≤
𝑥
< 17.8.2
gitlabgitlab
17.8.0 ≤
𝑥
< 17.8.2
𝑥
= Vulnerable software versions