Information Disclosure Vulnerability in GitLab EE
CVE-2025-11247
4.3MEDIUM
What is CVE-2025-11247?
GitLab EE has a vulnerability that allows authenticated users to exploit poorly configured GraphQL queries, potentially leading to unauthorized disclosure of sensitive information from private projects. This affects a wide range of GitLab EE versions, enabling attackers to gain insight into data that should remain confidential, emphasizing the importance of proper access controls and code auditing.
Affected Version(s)
GitLab 13.2 < 18.4.6
GitLab 18.5 < 18.5.4
GitLab 18.6 < 18.6.2
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Thanks [weasterhacker](https://hackerone.com/weasterhacker) for reporting this vulnerability through our HackerOne bug bounty program