Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-2498


An improper access control in Gitlab EE affecting all versions from 12.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that under certain conditions could have allowed users to view assigned issues from restricted groups by bypassing IP restrictions.


Published

2025-08-13T18:15:30.657

Last Modified

2025-08-15T16:25:17.323

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 3.1 (LOW)

Weaknesses
  • Type: Primary
    CWE-1220

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 18.0.6 Yes
Application gitlab gitlab < 18.1.4 Yes
Application gitlab gitlab < 18.2.2 Yes

References