CVE-2025-14595

EUVD-2025-208995
GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that under certain conditions could have allowed an authenticated user with Planner role to view security category metadata and attributes in group security configuration due to improper access control
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
GitLabCNA
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
gitlabgitlab
18.6.0 ≤
𝑥
< 18.8.7
gitlabgitlab
18.6.0 ≤
𝑥
< 18.8.7
gitlabgitlab
18.9.0 ≤
𝑥
< 18.9.3
gitlabgitlab
18.9.0 ≤
𝑥
< 18.9.3
gitlabgitlab
18.10.0
gitlabgitlab
18.10.0
𝑥
= Vulnerable software versions