Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-2045


Improper authorization in GitLab EE affecting all versions from 17.7 prior to 17.7.6, 17.8 prior to 17.8.4, 17.9 prior to 17.9.1 allow users with limited permissions to access to potentially sensitive project analytics data.


Published

2025-03-06T13:15:12.553

Last Modified

2025-08-06T18:33:48.627

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.3 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-863

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 17.7.6 Yes
Application gitlab gitlab < 17.8.4 Yes
Application gitlab gitlab 17.9.0 Yes

References