A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs.
2025-05-23T13:15:25.530
2025-08-08T18:25:10.470
Analyzed
CVSSv3.1: 3.5 (LOW)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | gitlab | gitlab | < 17.10.7 | Yes |
Application | gitlab | gitlab | < 17.10.7 | Yes |
Application | gitlab | gitlab | < 17.11.3 | Yes |
Application | gitlab | gitlab | < 17.11.3 | Yes |
Application | gitlab | gitlab | 18.0.0 | Yes |
Application | gitlab | gitlab | 18.0.0 | Yes |