Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-8770


An issue has been discovered in GitLab EE affecting all versions from 18.0 prior to 18.0.6, 18.1 prior to 18.1.4, and 18.2 prior to 18.2.2 that could have allowed authenticated users with specific access to bypass merge request approval policies by manipulating approval rule identifiers.


Published

2025-08-13T18:15:33.250

Last Modified

2025-08-15T16:33:45.953

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-639

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application gitlab gitlab < 18.0.6 Yes
Application gitlab gitlab < 18.1.4 Yes
Application gitlab gitlab < 18.2.2 Yes

References