CVE-2025-2045

EUVD-2025-6184
Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1  allow users with limited permissions to access to potentially sensitive project analytics data.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
gitlabgitlab
17.7.0 ≤
𝑥
< 17.7.6
gitlabgitlab
17.8.0 ≤
𝑥
< 17.8.4
gitlabgitlab
17.9.0
𝑥
= Vulnerable software versions