CVE-2025-14103
EUVD-2025-20811625.02.2026, 20:20
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.7 before 18.7.5, 18.8 before 18.8.5, and 18.9 before 18.9.1 that could have allowed an unauthorized user with Developer-role permissions to set pipeline variables for manually triggered jobs under certain conditions.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| gitlab | gitlab | 17.7.0 ≤ 𝑥 < 18.7.5 |
| gitlab | gitlab | 17.7.0 ≤ 𝑥 < 18.7.5 |
| gitlab | gitlab | 18.8.0 ≤ 𝑥 < 18.8.5 |
| gitlab | gitlab | 18.8.0 ≤ 𝑥 < 18.8.5 |
| gitlab | gitlab | 18.9.0 |
| gitlab | gitlab | 18.9.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration