Authentication Bypass Vulnerability in GitLab Provides Unauthorized Access
CVE-2025-11702
What is CVE-2025-11702?
An authentication bypass vulnerability in GitLab's Enterprise Edition has been identified, affecting multiple versions. An authenticated attacker with specific permissions could exploit this flaw to hijack project runners from other projects. This situation arises in versions 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1. GitLab has released patches to address this security issue, urging users to upgrade to the latest versions to maintain their projects' security and ensure proper permission integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
GitLab 17.1 < 18.3.5
GitLab 18.4 < 18.4.3
GitLab 18.5 < 18.5.1
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved